Role-Based Access Control
XACML supports RBAC - role based access control - by mapping users and roles on XACML
subjects, objects on resources and actions on XACML actions.
User-role relations and access control are expressed using policies. Roles and access rights are specified in different types of policies. We call the policies specifying the roles as role policies referring via policy references to its access rights specified in permission policies.