Grant.
Who may do what, where, in which mode, within which limits
Figure 1Grantspecified
- kind
- definition
- scope
- tenant
- key
- who, what and where, versioned
- store
- postgres
- family
- people
Fields#
| field | type | required | note |
|---|---|---|---|
who | GrantHolder | yes | |
permissions | Permission | yes | named one by one, by what they do, or by reach |
reach | AccessScope | no | the access scope the permissions were named by, where they were named by reach |
where | Scope | yes | |
data_group | id | no | |
mode | one of read only | propose | act | full autonomy | yes | |
limits | GrantLimits | yes | |
turned_on_by | Caller | no | for full autonomy: who, explicitly, for this one scope |
ends_at | time | no |
Routes that use it#
/v1/act/grantreturns it