Skip to main content

RBAC Architecture & Role Definitions (L0โ€“L4)

Dokumentasi lengkap Role-Based Access Control (RBAC) multi-level untuk sistem MStore yang dapat scale dari Micro business hingga Multi-National Corporation (MNC) dengan 57 roles terstruktur.

๐ŸŽฏ Prinsip Desain

Arsitektur ini dibangun berdasarkan 4 pilar utama:

Security

Principle of Least Privilege & Segregation of Duties

Efficiency

Role dapat dirangkap aman untuk tim kecil (kurang dari 50 staff)

Auditability

Semua transaksi critical ada trail & approval log

Scalability

Mudah upgrade dari L1 ke L4 tanpa breaking change

๐Ÿ“Š Level Overview

Total: 57 roles across 5 business levels

๐Ÿงฉ L0 โ€” Micro / Solo

๐ŸŽฏ Fokus: Sistem sederhana untuk 1โ€“3 user tanpa approval flow ๐Ÿ’ผ Contoh Bisnis: Warung, freelancer, jasa kecil

Roles

Karakteristik

  • โœ… Simple & Fast: Setup < 5 menit
  • โœ… No SoD: Tidak ada aturan rangkap jabatan
  • โœ… Single Device: Ideal untuk POS mini
  • โš ๏ธ No Approval: Tidak ada workflow approval

๐Ÿงฉ L1 โ€” SME (Smallโ€“Medium Enterprise)

๐ŸŽฏ Fokus: ERP dasar โ€” Finance, HR, Inventory ๐Ÿ’ผ Contoh Bisnis: Toko retail, bengkel, cafe, grosir kecil

Roles

Karakteristik

  • โœ… Efisien: Cukup 6 role untuk 5-20 staff
  • โœ… Tanpa konflik: Belum ada SoD strict
  • โœ… Rangkap aman: 1 orang boleh > 1 role
  • โš ๏ธ Basic approval: Approval sederhana saja

๐Ÿงฉ L2 โ€” Enterprise

๐ŸŽฏ Fokus: Multi-department, approval flow, RBAC penuh ๐Ÿ’ผ Contoh Bisnis: Manufaktur, e-commerce besar, distribusi

Core Roles (24 total)

  • L2_OWN-MGR: Akses penuh & approval tertinggi
  • L2_ADM-BIZ: Konfigurasi bisnis (COA, tax, workflow)
  • L2_ADM-SYS: Infrastruktur teknis (deployment, backup)

Segregation of Duties (SoD)

Critical SoD Rules untuk L2+:
  1. ADM-SYS โ‰  FIN.* atau HR.* (System admin tidak boleh akses finance)
  2. FIN-AP โ‰  ACC-MGR (Tidak boleh self-approve pembayaran)
  3. SL-POS โ‰  ACC-MGR (Kasir tidak boleh edit jurnal)
  4. AUD = Read-only saja (Auditor tidak boleh edit data)
  5. MKT-MGR โ‰  FIN-MGR (Marketing tidak boleh approve finance)
  6. CRM-OPS โ‰  IT-SYS (Pemisahan CRM operations vs infrastructure)
  7. RD-MGR โ‰  INV-MGR (R&D tidak boleh edit inventory production)
  8. DATA-ANL โ‰  FIN-AP (Data analyst tidak boleh input pembayaran)

Karakteristik

  • โœ… SoD Aktif: Segregation of Duties enforcement
  • โœ… Approval Flow: Multi-level approval (L1, L2)
  • โœ… Department-based: Role per departemen
  • โœ… Audit Trail: Lengkap untuk semua transaksi

๐Ÿงฉ L3 โ€” Holding

๐ŸŽฏ Fokus: Multi-entitas, multi-currency, intercompany ๐Ÿ’ผ Contoh Bisnis: Grup usaha dengan beberapa anak perusahaan

Holding-Level Roles (9 total)

Domain Architecture

Karakteristik

  • โœ… Domain Isolation: Role terisolasi per entitas
  • โœ… Intercompany: Support transaksi antar entitas
  • โœ… Consolidation: Laporan konsolidasi grup
  • โœ… Multi-Currency: Support mata uang berbeda

๐Ÿงฉ L4 โ€” Corporate / MNC

๐ŸŽฏ Fokus: Multi-country, regulatory compliance, SSO, OPA ๐Ÿ’ผ Contoh Bisnis: Grup lintas negara, public company

Global Roles (15 total)

Integration Stack

Identity & Access

  • SSO (SAML, OAuth2)
  • LDAP/Active Directory
  • MFA enforcement

Policy Engine

  • OPA (Open Policy Agent)
  • Casbin multi-domain
  • Redis Watcher (real-time sync)

Compliance

  • SOX compliance
  • ISO 27001
  • GDPR ready

Monitoring

  • Audit log central
  • SIEM integration
  • Anomaly detection

Karakteristik

  • โœ… Global Compliance: SOX, ISO, GDPR
  • โœ… SSO Integration: Single sign-on
  • โœ… Zero-Trust: OPA policy enforcement
  • โœ… Real-time Sync: Redis watcher untuk policy
  • โœ… Multi-Region: Support deployment global

๐Ÿ”„ Upgrade Path

Evolusi Natural

Migration Strategy

1

L0 โ†’ L1

Trigger: Staff bertambah > 3 orangAction:
  • Tambah role FIN-MGR, INV-MGR, HR-MGR
  • Pisahkan owner dari operator
  • Setup basic audit (role AUD)
2

L1 โ†’ L2

Trigger: Multi-department atau staff > 20 orangAction:
  • Aktifkan SoD rules
  • Split admin (ADM-BIZ vs ADM-SYS)
  • Implementasi approval flow (APV-L1, APV-L2)
  • Pisah finance (FIN-AP, FIN-AR, FIN-CASH)
3

L2 โ†’ L3

Trigger: Multi-entity atau holding structureAction:
  • Aktifkan domain isolation
  • Setup consolidation (CONS-MGR)
  • Tambah entity-level roles (@ENT-xx)
  • Implementasi intercompany transactions
4

L3 โ†’ L4

Trigger: Multi-country atau go publicAction:
  • Integrasikan SSO (SAML/OAuth2)
  • Deploy OPA untuk global policy
  • Setup compliance (GOV-COMP)
  • Aktifkan Redis watcher

๐Ÿ› ๏ธ Implementasi Teknis

Database Schema

Backend (Go/Fiber)

Casbin Policy


๐Ÿ“š Best Practices

1. Role Assignment

DO: Assign role berdasarkan fungsi, bukan orang

2. Segregation of Duties

Jangan pernah gabungkan roles ini:
  • L2_ADM-SYS + L2_FIN.* (System admin tidak boleh akses finance)
  • L2_FIN-AP + L2_ACC-MGR (Self-approval)
  • L2_SL-POS + L2_ACC-MGR (Kasir edit jurnal)
  • L3_AUD + ANY-WRITE (Auditor harus read-only)

3. Upgrade Timing


๐Ÿงช Testing & Validation

Role Validation Script

Casbin Policy Test


Bruno API Collections

API V2 collections organized by role

UI/UX by Level

UI/UX specifications for each business level

Approval Flow

Multi-level approval workflow

Audit Logs

Tracking aktivitas user per role

User Management

Cara assign role ke user

Security Best Practices

Panduan keamanan sistem

๐ŸŽ“ Example Scenarios

Scenario 1: Toko Retail (L1)

Setup:
  • 1 Owner (L1_OWN-MGR)
  • 1 Kasir (L1_CSH)
  • 1 Admin Stok (L1_INV-MGR)
  • 1 Keuangan part-time (L1_FIN-MGR)
Rangkap Jabatan:
  • Owner merangkap HR-MGR (aman karena L1 belum strict SoD)
  • Kasir merangkap VWR untuk lihat laporan (aman)

Scenario 2: Manufaktur (L2)

Setup:
  • 1 Owner (L2_OWN-MGR)
  • 2 Admin (L2_ADM-BIZ, L2_ADM-SYS) โ€” harus pisah!
  • Finance team: L2_FIN-AP, L2_FIN-AR, L2_ACC-MGR โ€” tidak boleh rangkap!
  • Operations: L2_INV-MGR, L2_PRC-MGR, L2_SL-MGR
  • Approvers: L2_APV-L1, L2_APV-L2
SoD Strict:
  • L2_FIN-AP โ‰  L2_ACC-MGR (tidak boleh self-approve)
  • L2_ADM-SYS โ‰  L2_FIN.* (system admin tidak boleh edit keuangan)

Scenario 3: Holding Group (L3)

Setup:
  • HOLDING: L3_CONS-MGR, L3_AUD-GRP, L3_APV-L3
  • ENT-01 (Trading): L3_FIN-MGR@ENT-01, L3_INV-MGR@ENT-01
  • ENT-02 (Manufacturing): L3_FIN-MGR@ENT-02, L3_INV-MGR@ENT-02
Domain Isolation:
  • L3_FIN-MGR@ENT-01 hanya akses data ENT-01
  • L3_CONS-MGR@HOLDING bisa akses semua entity

๐Ÿ“ž Support

Jika ada pertanyaan tentang multi-level RBAC atau butuh konsultasi untuk upgrade level, hubungi tim development. Tags: rbac, multi-level, security, scalability, casbin, enterprise, architecture, roles