People, scope and rights.
People, scope and rights: the 13 calls this system serves, each a route of the API and a tool of the MCP server, at contract 0476e35e6e275db5.
Figure 1People, scope and rightsspecified
People, scope and rights
The 13 calls below are the whole of this system on the wire: each is one route of the API and one tool of the MCP server, with one typed input, one card as its answer and one refusal shape. Every answer carries its foot: what was read, the population and the control.
The calls#
| tool | route | takes | gives |
|---|---|---|---|
| si.session.my_grants | POST /v1/session/my_grants | the caller, and a place | its permissions there, after all three narrowings |
| si.session.my_scopes | POST /v1/session/my_scopes | the caller | the scopes it reads, set on the database transaction before any query runs |
| si.session.sign_out | POST /v1/session/sign_out | the session or the user | nothing |
| si.session.whoami | POST /v1/session/whoami | a token, a key, or a run’s identity | the caller, with its scopes and its access scopes |
| si.read.consent | POST /v1/read/consent | the person or tenant, and the use | a fact. Or yes or no, with the fact that decides |
| si.read.invitations | POST /v1/read/invitations | nothing | the invitations with their states |
| si.read.receipts | POST /v1/read/receipts | the kind, export or erasure | the receipts |
| si.act.erase_person | POST /v1/act/erase_person | the person | the erasure as work, then its receipt |
| si.act.export_tenant | POST /v1/act/export_tenant | nothing | the export as work, then its receipt |
| si.act.grant | POST /v1/act/grant | the grant, by a caller who may give it | the grant’s new version |
| si.act.invite | POST /v1/act/invite | an address and a role | the invitation, open, with its expiry |
| si.act.membership | POST /v1/act/membership | the person’s address, and the roles with where each is held | the membership |
| si.act.sign_up | POST /v1/act/sign_up | the company’s name, and its domain where known, from a signed-in person who belongs to no tenant | the tenant, made on the trial plan with the person as its first member and owner, in one transaction with its events |
The bars this system enforces#
Every bar is a row of the parameter register: an administrator changes it, and the platform reads it by name at the place of enforcement the row records.
| parameter | family | dimension | enforced at |
|---|---|---|---|
| the longest life of a token | machinery | a time | the API gateway’s short list of ended tokens, which is never longer than it |
| the interval between fetches of a provider’s keys | machinery | a time | the API gateway |
| a grant’s limits: its budget by kind, its rate and its end date | receive | units of a kind; calls in a time; a date | the single authorization check before any action |
| the longest wait of a removal request | machinery | a time | the removal’s reader, which notifies a user past it |
Claims#
| claim | state | route or tool |
|---|---|---|
| The platform serves 13 calls of People, scope and rights at contract 0476e35e6e275db5. | target | si.session.my_grants |