RBAC (Role-Based Access Control)
Role-Based Access Control.
Quick Definition
RBAC is a security management method that restricts system access only to authorized users, based on the roles they perform within the organization. Instead of assigning permissions individually, the administrator defines access profiles ensuring that each employee or system has only the tools and data necessary for their tasks.
How the Market Understands This Concept
Traditionally, RBAC is seen as a layer of IT governance and compliance. In CRM, Marketing Automation, or ERP tools, it serves to separate what a "Salesperson" can see (their own leads) from what a "Manager" can access (consolidated team reports). It is the backbone of data security, ensuring that sensitive information does not leak and that critical actions are performed only by qualified personnel.
Why This Concept Matters
RBAC is vital for operational efficiency and customer trust. It reduces human error by simplifying the interface to what is relevant to the user, accelerates the onboarding of new employees, and is a non-negotiable requirement for compliance with laws like the GDPR (or LGPD). Without it, the integrity of the database is compromised, directly impacting the accuracy of business decisions and the company's legal security.
The Limit of the Traditional View
The traditional view of RBAC is static and silo-focused. It assumes that roles are fixed and strictly human. In a modern ecosystem, where AI Agents and autonomous systems interact directly with the customer, conventional RBAC fails by not providing permissions for "non-human identities" that need to query real-time contextual data to make service or offer decisions.
How MCI Expands This Concept
In Marketing Conversacional Integrado, RBAC evolves to include the IAm (AI Identity) and the protection of the Bandeja de Contexto. It is not just about "who" accesses, but "which intelligence" has permission to manipulate conversational memory data. MCI understands that RBAC must govern how the IA accesses customer history to prevent sensitive information from being exposed in a chat, ensuring the conversation flows securely while the IA acts as a digital proxy with clear limits of autonomy.
Practical Example
A customer contacts a company via WhatsApp to dispute an invoice. The AI Agent (with specific RBAC) can query the payment status but does not have permission to issue a refund exceeding $500.00. When the conversation reaches this decision limit, the system's RBAC triggers the Guardião do Ciclo, which handoffs the service to a human supervisor. This human, in turn, has an access profile that allows them to view the full history (Bandeja de Contexto) and authorize the credit, ensuring the decision flow is secure and fluid.
Common Error
Confusing RBAC with individual permissions (ACL). Many companies try to manage access by editing user by user, which generates Memory Gaps and security failures. When an employee changes departments, they retain old access rights, creating vulnerabilities and disorder in customer context management.
In the Dynamic Journey
In the dynamic journey, RBAC needs to be agile. If a customer moves from a "Discovery" state to "Negotiation," the system must ensure that the agents (human or IA) interacting with them have the necessary permissions to access contract and price data at that exact moment, without access bureaucracy interrupting the conversation flow or creating friction in the experience.
Relationship with the 8Cs
- Trust (Confiança): RBAC ensures that customer data is handled only by those who have the right, strengthening the security bond.
- Consistency: It allows the brand experience to be uniform, as the actions taken by agents (IA or humans) follow the rules and limits established by the role.
- Context: It defines which parts of the customer history are accessible to inform the next interaction without violating privacy.
Related Metrics
- Mean Time to Resolution (MTTR): Optimized when RBAC is well-configured and agents have the right tools at hand.
- Data Vulnerability Index: Number of unauthorized accesses or blocked attempts.
- Correct Handoff Rate: Percentage of conversations moved to the correct access profile when the IA reaches its permission limit.
Connected MCI Terms
- IAm: The definition of specific roles and permissions for autonomous agents.
- Bandeja de Contexto: The secure handling of data that RBAC protects during an interaction.
- Guardião do Ciclo: The role that monitors whether business and access rules are being respected in the journey.
Executive Summary
RBAC (Role-Based Access Control) ceases to be just a technical IT configuration to become a strategic pillar in MCI. By defining who (or which IA) can see and do what, the company ensures a scalable, secure operation free from operational amnesia. In a scenario where the conversation is the unit of value, RBAC is what ensures this conversation occurs within ethical, legal, and commercial guardrails, protecting the integrity of the customer journey.