Kaizen
Browse modulesAccessaccess/serverTypes

Type Alias: CreateVersionOptions

type CreateVersionOptions = 
  | {
  mode: "system";
}
  | {
  guard: CreateVersionGuard;
  mode: "guarded";
};

Defined in: server/access/role-service.ts:52

Discriminated authorization mode for the role-edit (createVersion) path — the twin of CreateGrantOptions. Exactly one mode is REQUIRED when the patch adds/changes permissions; omitting it (or passing guarded with no guard) fails closed (C3, role-edit twin).

  • guarded — the org-facing path: the actor's held permissions gate the edit (role-edit subset check).
  • system — the trusted seed/bootstrap bypass: the subset check is skipped. NEVER reachable from caller-supplied input; systemManaged-role protection still applies.