Solia saysRole-based access control replaces a single owner with a matrix of (role → addresses) — letting the protocol grant minting, pausing, and upgrading independently.
The simplest access control is Ownable: one owner address, one onlyOwner modifier. It does not scale: real protocols need separate authorities for minting, pausing, treasury moves, and parameter changes. Role-based access control (OpenZeppelin's AccessControl) maps role identifiers to sets of authorized addresses, and gates each function with a onlyRole(X) check.
Beyond static roles, EIP-5313 / AccessManager generalize to per-function delegation with time-bounded grants. The demo runs four calls against a role matrix and shows allowed vs reverted outcomes.
Power-ups you unlock
Ownable: single owner, all-or-nothing
AccessControl: role IDs → sets of addresses
Each function gates on a specific role (onlyRole)
Roles can be granted/revoked independently
AccessManager generalizes to per-function delegation
The Reentrancy Reaper attacks — common mistakes
Leaving the default admin role with a single EOA
Granting roles without expiration or revocation plan
Using a single role for incompatible privileges
Forgetting events on role changes (auditability)
Boss battleBuild a 3-role matrix (OWNER/MINTER/PAUSER) and verify 4 calls against it.