Type Alias: CreateVersionOptions
type CreateVersionOptions =
| {
mode: "system";
}
| {
guard: CreateVersionGuard;
mode: "guarded";
};Defined in: server/access/role-service.ts:52
Discriminated authorization mode for the role-edit (createVersion) path —
the twin of CreateGrantOptions. Exactly one mode is REQUIRED when the patch
adds/changes permissions; omitting it (or passing guarded with no guard)
fails closed (C3, role-edit twin).
guarded— the org-facing path: the actor's held permissions gate the edit (role-edit subset check).system— the trusted seed/bootstrap bypass: the subset check is skipped. NEVER reachable from caller-supplied input; systemManaged-role protection still applies.