Attribute-based access control (ABAC) helps teams grant the right people access to the right records without overbroad permissions.
A familiar access problem shows up in almost every growing governance program.
A security administrator gets a request from someone who needs access to one specific record: one assessment for legal review, one policy for approval, one vendor record for onboarding, or one AI model for cross-functional input. The ask is narrow, but the access options are often broad. Too often, the choice becomes granting a wider role than the situation requires or creating another exception that adds complexity to the environment.
That is why ABAC matters.
If you're responsible for administering access, supporting governance workflows, or reducing operational risk, ABAC adds precision. It helps teams collaborate on the records they need without opening access more broadly than intended. For managers and the CISO office, it offers a practical way to support least-privileged access while keeping work moving.
In OneTrust, ABAC currently supports record-level access control. It complements role-based access control (RBAC), which continues to serve its own baseline permission use cases. ABAC adds another layer of control by determining which specific records those permissions should apply to.
What Is ABAC?
At a practical level, ABAC adds record-level control in the OneTrust AI-Ready Governance PlatformTM. Instead of granting broad access to every assessment, policy, vendor, or AI model, ABAC allows granting access to the specific records they need.
That matters because governance workflows often involve temporary approvers, regional stakeholders, business owners, legal reviewers, security teams, and external collaborators. In those moments, ABAC provides a more targeted way to enable work without expanding access beyond what is necessary.
The foundation centers on five capabilities: direct sharing, request access, assignments, manage access, and auditing.
How ABAC Works
The core concept is the assignment. An assignment defines what a user can do with a record, including actions such as viewing, editing, commenting, completing tasks, sharing, or managing access.
Access can be granted in three main ways:
- Direct sharing: A user with the right permissions can share a specific record with another user and define the assignment that person should receive.
- Record attributes: For example, if a business owner is associated with a record, that relationship can determine their access to it. This is what makes ABAC valuable in practice: access is tied to context, not just to a static role.
- Workflows: An admin can set up a workflow to automatically share an assignment with a user identified in that workflow. For example, a user added as a risk approver via workflow automation would automatically be assigned to the workflow, enabling them to access the created risk.