Kaizen
Browse modulesAccessaccess/sharedFunctions

Function: definePermissions()

function definePermissions<K extends `${string}.${string}`>(defs: Record<K, PermissionDef>): PermissionCatalog<K>;

Defined in: shared/access/registry.ts:40

Declare the authoritative permission catalog in code. The RbacPermissions table is an optional mirror for admin UX; this catalog is the source of truth — deny-by-default means an undeclared action is never delegable.

Type Parameters

Type Parameter
K extends `${string}.${string}`

Parameters

ParameterType
defsRecord<K, PermissionDef>

Returns

PermissionCatalog<K>

Example

const catalog = definePermissions({
  "product.publish":   { delegable: true },
  "team.assignOwner":  { delegable: false },
  "access.grant.create": { delegable: false },
});

On this page