IT Glossary

Fine-Grained Access Control

Fine-grained access control decides permissions at record and field level. Learn how it works, what it costs to run, and when coarse control is enough.

August 7, 2026

What is fine-grained access control?

Fine-grained access control is an approach that decides permissions at the level of individual records, fields, or actions rather than whole applications. Where coarse-grained control answers whether a user can open the CRM, fine-grained control answers whether that user can see the revenue field on one specific account. It is usually implemented with attribute-based or relationship-based policies.

How fine-grained access control works

  • Policies evaluate attributes at run time: user role, department, record owner, data classification, device, and time.
  • The decision point sits inside the application or in an external authorization service.
  • Rules combine conditions, for example allowing read access to opportunities whose owner belongs to the requester region.
  • Row-level and column-level security in databases are the classic implementations.
  • Every decision can be logged, which is what makes the control provable in an audit.

What fine-grained control costs to run

Granularity is not free. Each additional condition is a rule someone has to write, test, and maintain, and complex policy sets become their own source of risk once nobody can say what they actually do. The practical rule is to keep coarse control as the default and reserve fine-grained rules for data that genuinely warrants them: financial records, personal data under the GDPR, and customer information.

Examples and use cases

A company running a shared CRM across three countries needs each sales team to see only its own region, while finance sees every deal but not the notes fields. Roles alone cannot express that, so attribute-based rules handle it at record and field level. The governance question that follows is who reviews those rules and how often. Corma brings application-level rights into one recurring review, so scope decisions stay visible instead of living inside each admin console.

Related concepts

FAQ

What is the difference between coarse-grained and fine-grained access control?

Coarse-grained control decides access to an application or a whole module. Fine-grained control decides access to individual records, fields, or actions inside it.

Is fine-grained access control the same as ABAC?

Not exactly. ABAC is the model that evaluates attributes, while fine-grained access control is the level of granularity that ABAC makes achievable.

Does RBAC support fine-grained control?

Only up to a point. Expressing record-level conditions in pure RBAC requires creating a role for every combination, which quickly becomes unmanageable.

When is fine-grained access control worth the effort?

When the data inside one application is not uniformly sensitive, typically in financial systems, HR platforms, healthcare records, and multi-region CRMs.

Request a demo