Kaizen
Browse modulesAccessaccess/serverTypes

Type Alias: CreateGrantOptions

type CreateGrantOptions = 
  | {
  mode: "system";
}
  | {
  guard: CreateGrantGuard;
  mode: "guarded";
};

Defined in: server/access/grant-service.ts:69

Discriminated authorization mode for the create path. Exactly one mode is REQUIRED — omitting it (or passing guarded with no guard) fails closed (C3).

  • guarded — the org-facing path: the actor's derived permissions + footing gate the grant (subset check, role-assignment gate, maxAssignableScope).
  • system — the trusted seed/bootstrap bypass: those escalation guards are skipped. NEVER reachable from caller-supplied input; the platform-scope invariant and attribute-registry checks still apply. Naming the mode "system" makes the bypass self-documenting at every call site (vs. the old ambiguous { system: true } boolean).

revoke takes the SAME options: revocation is gated by the same verdict as creation.