ABAC relies on policies that are driven by *attributes of the users*. This allows for complex rulesets based on combinations of attributes that provide users with specific rights that match the attributes they have. Attribute-based access control schemes are useful for application security, where they are often used for enterprise systems that have complex user roles and rights that vary depending on the way and role that users interact with a system. They're also used with databases and content management systems, microservices, and APIs for similar reasons.