Kaizen
Browse modulesAccessaccess/serverInterfaces

Interface: AccessDecisionEntry

Defined in: server/access/deps.ts:27

A qualifying authorization decision handed to the consumer's onDecision hook. Shape mirrors the rbac_decision_log row — policy references + condition outcomes (the trace), NEVER full resource payloads (only a resourceId/resourceType reference). The consumer owns the audit store, retention, and any PII redaction; the shipped createTableDecisionSink adapter persists this entry to rbac_decision_log for those who opt in.

Properties

action

action: string;

Defined in: server/access/deps.ts:38


allowed

allowed: boolean;

Defined in: server/access/deps.ts:41


organizationId

organizationId: string | null;

Defined in: server/access/deps.ts:34

The TARGET scope of the check — what was accessed. A platform-held grant can authorize an organization-scoped request; when it does these still name the organization, and the trace's per-entry scopeKey names the scope the matching grant came from.


reason

reason: string;

Defined in: server/access/deps.ts:42


resourceId

resourceId: string | null;

Defined in: server/access/deps.ts:40


resourceType

resourceType: string | null;

Defined in: server/access/deps.ts:39


scopeKey

scopeKey: string;

Defined in: server/access/deps.ts:35


subjectId

subjectId: string;

Defined in: server/access/deps.ts:37


subjectType

subjectType: SubjectType;

Defined in: server/access/deps.ts:36


trace

trace: DecisionTraceEntry[];

Defined in: server/access/deps.ts:43

On this page