Interface: AccessDecisionEntry
Defined in: server/access/deps.ts:27
A qualifying authorization decision handed to the consumer's onDecision
hook. Shape mirrors the rbac_decision_log row — policy references +
condition outcomes (the trace), NEVER full resource payloads (only a
resourceId/resourceType reference). The consumer owns the audit store,
retention, and any PII redaction; the shipped createTableDecisionSink
adapter persists this entry to rbac_decision_log for those who opt in.
Properties
action
action: string;Defined in: server/access/deps.ts:38
allowed
allowed: boolean;Defined in: server/access/deps.ts:41
organizationId
organizationId: string | null;Defined in: server/access/deps.ts:34
The TARGET scope of the check — what was accessed. A platform-held grant
can authorize an organization-scoped request; when it does these still
name the organization, and the trace's per-entry scopeKey names the
scope the matching grant came from.
reason
reason: string;Defined in: server/access/deps.ts:42
resourceId
resourceId: string | null;Defined in: server/access/deps.ts:40
resourceType
resourceType: string | null;Defined in: server/access/deps.ts:39
scopeKey
scopeKey: string;Defined in: server/access/deps.ts:35
subjectId
subjectId: string;Defined in: server/access/deps.ts:37
subjectType
subjectType: SubjectType;Defined in: server/access/deps.ts:36
trace
trace: DecisionTraceEntry[];Defined in: server/access/deps.ts:43