Function: evaluateAccess()
function evaluateAccess(
snapshot: PermissionSnapshot,
request: AccessRequest,
options?: EvaluateAccessOptions
): Decision;Defined in: shared/access/kernel.ts:269
The pure evaluation kernel. Deny-by-default, ALLOW-only: a request is allowed iff at least one applicable grant (a) contains the action, (b) whose selector matches the resource, and (c) whose ABAC condition passes. Otherwise deny.
Emits a full trace — every grant the kernel consulted, whether it matched, and why (selector outcome, per-condition outcomes). No DB access happens here; the snapshot is the only input. This is the explainability guarantee in one function.
Parameters
| Parameter | Type |
|---|---|
snapshot | PermissionSnapshot |
request | AccessRequest |
options | EvaluateAccessOptions |