[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-08-21 (世界標準時間)。"],[[["\u003cp\u003eData RBAC (role-based access control) restricts user access to data based on their organizational roles, ensuring they can only access data necessary for their job.\u003c/p\u003e\n"],["\u003cp\u003eData RBAC works in conjunction with feature RBAC, where feature RBAC controls access to system functionalities, and data RBAC controls access to specific data within those features.\u003c/p\u003e\n"],["\u003cp\u003eData RBAC allows administrators to define scopes and assign them to users, enabling granular control over data visibility and modification rights.\u003c/p\u003e\n"],["\u003cp\u003eData RBAC is supported in Google SecOps, with resources available to understand, set up, and evaluate its impact on features.\u003c/p\u003e\n"]]],[],null,["# Introduction to data RBAC\n=========================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\n*Data role-based access control* (*data RBAC*) is a security model that\nrestricts user access to data based on the user's roles within an\norganization. With data RBAC, administrators can define scopes and assign them\nto users to help ensure that users can access only the necessary data for their job\nfunctions.\n\nData RBAC and feature RBAC are often used together to provide a comprehensive\naccess control system. The differences are the following:\n\n- Feature RBAC controls access to specific features or\n functionalities within a system. Feature RBAC determines which features are accessible to\n users based on their roles.\n\n- Data RBAC controls access to specific data or\n information within a system. Data RBAC controls user access to view and\n modify data based on their roles.\n\nFor example, a user might be allowed to\naccess a specific feature (feature RBAC) and within that feature, their access\nto specific data might be further restricted based on their role (data RBAC).\n\nTo understand how data RBAC works, see [Overview of Data RBAC](/chronicle/docs/administration/datarbac-overview).\n\nFor information about the data RBAC impact on features, see [Data RBAC impact on features](/chronicle/docs/administration/datarbac-impact).\n\nTo get started with configuring data RBAC, see [Configure data RBAC](/chronicle/docs/administration/configure-datarbac-users).\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]