Epilogue: You Are the Architect

🏆 You have completed RBAC In Business.

You arrived as an Analyst, handed a mandate and a blank database. You leave as the Architect of Amasoft’s first centralised RBAC system - and with a production-grade foundation you can adapt for your own company.

The spreadsheets are retired. The compliance team has self-service audit queries. Alex Chen is a full-time employee with appropriate access. Sam Rivera’s promotion is recorded with full history. The Finance Integration project team has time-limited payments access. Separation of Duties is enforced by a short, readable function. And every access grant in the system is traceable back to a policy, an approver, and/or a reason.

Along the way you mastered:

  • A realistic identity hierarchy with abstract types and shared attributes

  • Reporting lines and department membership with cardinality constraints

  • An access model with schema-level permission validation

  • Level assignment as a time-tracked relation - non-destructive, history-preserving

  • Compliance audit queries across the full access model

  • Access policies as composable TypeQL functions - including Separation of Duties

  • Project team access and disjunctive path traversal with source labels

  • Schema evolution with define, undefine, and redefine; schema vs. data for modelling concepts

  • Sub-relations for specialised access types; sub-attributes to identify both humans and bots

  • Nested relations for access reviews - facts about facts

  • Production transactions, idempotent provisioning, and the principle of closing history rather than deleting it

The RBAC system you built is correct, auditable, and extensible. The Architect’s Checklist in Chapter Nine shows you exactly where to go next.

✦ Access granted. Architect confirmed. ✦