# Why Role-Based Access Control Isn't Enough for OT Security

DevFeed: [Why Role-Based Access Control Isn't Enough for OT Security](<https://devfeed.tech/articles/why-role-based-access-control-isn-t-enough-for-ot-security-51089.md>)

Original publisher: [Read original article](<https://www.portainer.io/blog/why-rbac-isnt-enough-for-ot-security>)

Author: Portainer

Published: 2026-06-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Portainer](<https://devfeed.tech/sources/portainer-blog.md>)

Topics: [Access Control](<https://devfeed.tech/topics/access-control.md>), [rbac](<https://devfeed.tech/topics/rbac.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [permission](<https://devfeed.tech/topics/permission.md>), [software-architecture](<https://devfeed.tech/topics/software-architecture.md>), [systems](<https://devfeed.tech/topics/systems.md>), [audit](<https://devfeed.tech/topics/audit.md>), [sessions](<https://devfeed.tech/topics/sessions.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [audit](<https://devfeed.tech/tags/audit.md>), [blog](<https://devfeed.tech/tags/blog.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [rbac](<https://devfeed.tech/tags/rbac.md>), [security](<https://devfeed.tech/tags/security.md>), [sessions](<https://devfeed.tech/tags/sessions.md>), [traceability](<https://devfeed.tech/tags/traceability.md>)

## AI overview

This article argues that role-based access control is insufficient for operational technology vendor access because it maps identities to permissions without enforcing time limits, device scope, or session traceability. It presents action-based access control, outbound-only connectivity, process-scoped permissions, and off-host audit logging as architectural controls for narrowing and recording vendor sessions.

## Source excerpt

The Vendor Access Problem: From Role-Based to Action-Based Control in OT Environments