RBAC Architecture & Role Definitions (L0โL4)
Dokumentasi lengkap Role-Based Access Control (RBAC) multi-level untuk sistem MStore yang dapat scale dari Micro business hingga Multi-National Corporation (MNC) dengan 57 roles terstruktur.๐ฏ Prinsip Desain
Arsitektur ini dibangun berdasarkan 4 pilar utama:Security
Principle of Least Privilege & Segregation of Duties
Efficiency
Role dapat dirangkap aman untuk tim kecil (kurang dari 50 staff)
Auditability
Semua transaksi critical ada trail & approval log
Scalability
Mudah upgrade dari L1 ke L4 tanpa breaking change
๐ Level Overview
Total: 57 roles across 5 business levels
๐งฉ L0 โ Micro / Solo
๐ฏ Fokus: Sistem sederhana untuk 1โ3 user tanpa approval flow ๐ผ Contoh Bisnis: Warung, freelancer, jasa kecilRoles
Karakteristik
- โ Simple & Fast: Setup < 5 menit
- โ No SoD: Tidak ada aturan rangkap jabatan
- โ Single Device: Ideal untuk POS mini
- โ ๏ธ No Approval: Tidak ada workflow approval
๐งฉ L1 โ SME (SmallโMedium Enterprise)
๐ฏ Fokus: ERP dasar โ Finance, HR, Inventory ๐ผ Contoh Bisnis: Toko retail, bengkel, cafe, grosir kecilRoles
Karakteristik
- โ Efisien: Cukup 6 role untuk 5-20 staff
- โ Tanpa konflik: Belum ada SoD strict
- โ Rangkap aman: 1 orang boleh > 1 role
- โ ๏ธ Basic approval: Approval sederhana saja
๐งฉ L2 โ Enterprise
๐ฏ Fokus: Multi-department, approval flow, RBAC penuh ๐ผ Contoh Bisnis: Manufaktur, e-commerce besar, distribusiCore Roles (24 total)
- Management (3)
- Finance (4)
- Operations (6)
- Marketing & CRM (4)
- Customer Service (2)
- R&D (2)
- Support (3)
- Approvers (2)
- L2_OWN-MGR: Akses penuh & approval tertinggi
- L2_ADM-BIZ: Konfigurasi bisnis (COA, tax, workflow)
- L2_ADM-SYS: Infrastruktur teknis (deployment, backup)
Segregation of Duties (SoD)
Karakteristik
- โ SoD Aktif: Segregation of Duties enforcement
- โ Approval Flow: Multi-level approval (L1, L2)
- โ Department-based: Role per departemen
- โ Audit Trail: Lengkap untuk semua transaksi
๐งฉ L3 โ Holding
๐ฏ Fokus: Multi-entitas, multi-currency, intercompany ๐ผ Contoh Bisnis: Grup usaha dengan beberapa anak perusahaanHolding-Level Roles (9 total)
Domain Architecture
Karakteristik
- โ Domain Isolation: Role terisolasi per entitas
- โ Intercompany: Support transaksi antar entitas
- โ Consolidation: Laporan konsolidasi grup
- โ Multi-Currency: Support mata uang berbeda
๐งฉ L4 โ Corporate / MNC
๐ฏ Fokus: Multi-country, regulatory compliance, SSO, OPA ๐ผ Contoh Bisnis: Grup lintas negara, public companyGlobal Roles (15 total)
Integration Stack
Identity & Access
- SSO (SAML, OAuth2)
- LDAP/Active Directory
- MFA enforcement
Policy Engine
- OPA (Open Policy Agent)
- Casbin multi-domain
- Redis Watcher (real-time sync)
Compliance
- SOX compliance
- ISO 27001
- GDPR ready
Monitoring
- Audit log central
- SIEM integration
- Anomaly detection
Karakteristik
- โ Global Compliance: SOX, ISO, GDPR
- โ SSO Integration: Single sign-on
- โ Zero-Trust: OPA policy enforcement
- โ Real-time Sync: Redis watcher untuk policy
- โ Multi-Region: Support deployment global
๐ Upgrade Path
Evolusi Natural
Migration Strategy
1
L0 โ L1
Trigger: Staff bertambah > 3 orangAction:
- Tambah role FIN-MGR, INV-MGR, HR-MGR
- Pisahkan owner dari operator
- Setup basic audit (role AUD)
2
L1 โ L2
Trigger: Multi-department atau staff > 20 orangAction:
- Aktifkan SoD rules
- Split admin (ADM-BIZ vs ADM-SYS)
- Implementasi approval flow (APV-L1, APV-L2)
- Pisah finance (FIN-AP, FIN-AR, FIN-CASH)
3
L2 โ L3
Trigger: Multi-entity atau holding structureAction:
- Aktifkan domain isolation
- Setup consolidation (CONS-MGR)
- Tambah entity-level roles (@ENT-xx)
- Implementasi intercompany transactions
4
L3 โ L4
Trigger: Multi-country atau go publicAction:
- Integrasikan SSO (SAML/OAuth2)
- Deploy OPA untuk global policy
- Setup compliance (GOV-COMP)
- Aktifkan Redis watcher
๐ ๏ธ Implementasi Teknis
Database Schema
Backend (Go/Fiber)
Casbin Policy
๐ Best Practices
1. Role Assignment
2. Segregation of Duties
3. Upgrade Timing
๐งช Testing & Validation
Role Validation Script
Casbin Policy Test
๐ Related Documentation
Bruno API Collections
API V2 collections organized by role
UI/UX by Level
UI/UX specifications for each business level
Approval Flow
Multi-level approval workflow
Audit Logs
Tracking aktivitas user per role
User Management
Cara assign role ke user
Security Best Practices
Panduan keamanan sistem
๐ Example Scenarios
Scenario 1: Toko Retail (L1)
Setup:- 1 Owner (L1_OWN-MGR)
- 1 Kasir (L1_CSH)
- 1 Admin Stok (L1_INV-MGR)
- 1 Keuangan part-time (L1_FIN-MGR)
- Owner merangkap HR-MGR (aman karena L1 belum strict SoD)
- Kasir merangkap VWR untuk lihat laporan (aman)
Scenario 2: Manufaktur (L2)
Setup:- 1 Owner (L2_OWN-MGR)
- 2 Admin (L2_ADM-BIZ, L2_ADM-SYS) โ harus pisah!
- Finance team: L2_FIN-AP, L2_FIN-AR, L2_ACC-MGR โ tidak boleh rangkap!
- Operations: L2_INV-MGR, L2_PRC-MGR, L2_SL-MGR
- Approvers: L2_APV-L1, L2_APV-L2
- L2_FIN-AP โ L2_ACC-MGR (tidak boleh self-approve)
- L2_ADM-SYS โ L2_FIN.* (system admin tidak boleh edit keuangan)
Scenario 3: Holding Group (L3)
Setup:- HOLDING: L3_CONS-MGR, L3_AUD-GRP, L3_APV-L3
- ENT-01 (Trading): L3_FIN-MGR@ENT-01, L3_INV-MGR@ENT-01
- ENT-02 (Manufacturing): L3_FIN-MGR@ENT-02, L3_INV-MGR@ENT-02
- L3_FIN-MGR@ENT-01 hanya akses data ENT-01
- L3_CONS-MGR@HOLDING bisa akses semua entity
๐ Support
Jika ada pertanyaan tentang multi-level RBAC atau butuh konsultasi untuk upgrade level, hubungi tim development. Tags:rbac, multi-level, security, scalability, casbin, enterprise, architecture, roles