In the typical medium-to-large company that has legacy implementations of a few decades' worth of processes, RBAC is absolutely infeasible. The legacy systems evolved to accommodate specific individuals who wore multiple hats, and now that those persons are gone, the processes that they left behind can only be worked on a cargo-cult basis.
detkin•1h ago
At some of the larger orgs that I've worked at each individual system had some level of RBAC. Often they would try to centralize around an Okta-style system, but the roles in there infrequently matched what was needed. In the places you are describing what have they done around security? Even without AI it sounds like they didn't have a feasible solution?
FrankWilhoit•1h ago
detkin•1h ago