Kaizen
Browse modulesAccessaccess/serverFunctions

Function: createTableDecisionSink()

function createTableDecisionSink(options?: AccessRepositoriesOptions): OnDecision;

Defined in: server/access/table-decision-sink.ts:35

Opt-in, table-backed onDecision adapter. Wires the consumer-facing audit hook to the shipped rbac_decision_log table (via DecisionLogRepository) in one line:

createAccessServices({
  getActorId,
  audit: "sensitive",
  onDecision: createTableDecisionSink(),
});

The default audit boundary remains the no-op hook — passing this sink is what turns on table persistence. It is fire-and-forget: each qualifying decision is appended through the ambient transaction machinery (joining an existing transaction when present), and any write failure is swallowed here (in addition to AccessService wrapping the hook), so a hook rejection cannot alter a returned can() decision. A SQL failure can still abort a shared outer transaction; this adapter provides no savepoint or independent durable commit.

Consumers wanting their own store (different DB, queue, retention, PII redaction) skip this and pass their own onDecision instead.

Parameters

ParameterType
optionsAccessRepositoriesOptions

Returns

OnDecision

On this page