---
title: "Grant"
description: "who may do what, where, in which mode, within which limits"
section: concepts
address: /concepts/grant
contract: 0476e35e6e275db5
---

# Grant

who may do what, where, in which mode, within which limits

[figure: Grant is a definition at tenant scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | definition |
| scope | tenant |
| key | who, what and where, versioned |
| store | postgres |
| family | people |



## Fields


| field | type | required | note |
|---|---|---|---|
| `who` | [GrantHolder](/concepts/grantholder) | yes |  |
| `permissions` | [Permission](/concepts/permission) | yes | named one by one, by what they do, or by reach |
| `reach` | [AccessScope](/concepts/accessscope) | no | the access scope the permissions were named by, where they were named by reach |
| `where` | [Scope](/concepts/scope) | yes |  |
| `data_group` | `id` | no |  |
| `mode` | `one of read only \| propose \| act \| full autonomy` | yes |  |
| `limits` | [GrantLimits](/concepts/grantlimits) | yes |  |
| `turned_on_by` | [Caller](/concepts/caller) | no | for full autonomy: who, explicitly, for this one scope |
| `ends_at` | `time` | no |  |



## Routes that use it
- [`/v1/act/grant`](/reference/act/grant) returns it
