Authorization and RBAC
RBAC assigns capabilities via roles, combined with resource scope.
What it is
RBAC assigns capabilities via roles, combined with resource scope.
When to use it
Keep role permissions explicit and verify ownership/tenant context.
Syntax
Gate::define("view-audits", fn (User $user) => $user->role === "auditor");Example
// Simplified policy, using controlled server-side role values:
public function approve(User $user, Transfer $transfer): bool
{
return $user->role === "approver"
&& $user->tenant_id === $transfer->tenant_id
&& $user->id !== $transfer->created_by
&& $transfer->status === "pending";
}Common mistakes
A broad admin role can bypass segregation of duties; never mass-assign roles from requests.