OpenShift uses Kubernetes RBAC unchanged, but adds convenience commands under oc adm policy and a few default cluster roles you will use constantly: admin, edit, view and self-provisioner.
Local vs cluster bindings
A RoleBinding grants permissions inside one project, even when it references a ClusterRole. A ClusterRoleBinding grants them everywhere.
oc adm policy add-role-to-user edit dev1 -n payments
oc adm policy add-role-to-group view qa-team -n payments
oc adm policy add-cluster-role-to-group cluster-admin platform-admins
Always verify
oc auth can-i create deployment --as=dev1 -n payments
oc get rolebindings -n payments -o wide
Restricting project creation
Self-provisioning is granted to all authenticated users by the self-provisioners cluster role binding. Removing that group from the binding — and setting the autoupdate annotation to false so it is not restored — is a classic exam task covered step by step in the study guide.

Red Hat OpenShift Administration EX280 Study Guide
Hands-On Labs, Practice Tasks, and Exam Strategies for the Red Hat Certified OpenShift Administrator
Get the book