Type Alias: CreateGrantOptions
type CreateGrantOptions =
| {
mode: "system";
}
| {
guard: CreateGrantGuard;
mode: "guarded";
};Defined in: server/access/grant-service.ts:69
Discriminated authorization mode for the create path. Exactly one mode is
REQUIRED — omitting it (or passing guarded with no guard) fails closed (C3).
guarded— the org-facing path: the actor's derived permissions + footing gate the grant (subset check, role-assignment gate, maxAssignableScope).system— the trusted seed/bootstrap bypass: those escalation guards are skipped. NEVER reachable from caller-supplied input; the platform-scope invariant and attribute-registry checks still apply. Naming the mode"system"makes the bypass self-documenting at every call site (vs. the old ambiguous{ system: true }boolean).
revoke takes the SAME options: revocation is gated by the same verdict as
creation.