Kaizen
Browse modulesAccessaccess/sharedFunctions

Function: evaluateAccess()

function evaluateAccess(
   snapshot: PermissionSnapshot, 
   request: AccessRequest, 
   options?: EvaluateAccessOptions
): Decision;

Defined in: shared/access/kernel.ts:269

The pure evaluation kernel. Deny-by-default, ALLOW-only: a request is allowed iff at least one applicable grant (a) contains the action, (b) whose selector matches the resource, and (c) whose ABAC condition passes. Otherwise deny.

Emits a full trace — every grant the kernel consulted, whether it matched, and why (selector outcome, per-condition outcomes). No DB access happens here; the snapshot is the only input. This is the explainability guarantee in one function.

Parameters

ParameterType
snapshotPermissionSnapshot
requestAccessRequest
optionsEvaluateAccessOptions

Returns

Decision

On this page