Most of us are used to thinking about access control in terms of roles: predefined sets of privileges assigned to subjects. But what if access could instead be determined by the relationships between people, resources, and organizations? In this talk, we’ll explore relationship-based access control (ReBAC)—an authorization paradigm where permissions are defined through the presence of relationships rather than static role assignments. We’ll look at the theory behind ReBAC and examine how it enables intuitive and flexible modeling of complex access requirements. Finally, we’ll see why ReBAC is particularly powerful in domains like healthcare, where strict regulations demand fine-grained, context-aware access control.