Kaizen
Browse modulesAccessaccess/sharedInterfaces

Interface: CompiledGrant

Defined in: shared/access/types.ts:140

A grant compiled for in-memory evaluation: the grant joined with the flat permission set of its (current) role version. This is what the kernel walks — no DB access happens inside evaluateAccess.

Properties

condition?

optional condition?: ConditionLogicNode;

Defined in: shared/access/types.ts:152


effectiveEnd?

optional effectiveEnd?: string | null;

Defined in: shared/access/types.ts:154


effectiveStart?

optional effectiveStart?: string | null;

Defined in: shared/access/types.ts:153


grantId

grantId: string;

Defined in: shared/access/types.ts:141


permissions

permissions: `${string}.${string}`[];

Defined in: shared/access/types.ts:150


roleId

roleId: string;

Defined in: shared/access/types.ts:142


roleIdentifier

roleIdentifier: string;

Defined in: shared/access/types.ts:143


scope

scope: GrantScope;

Defined in: shared/access/types.ts:149

The scope this grant was GRANTED IN — per row, never the scope of the check. An organization-scoped check carries platform rows here (see scopeChain); footing derivation and the decision trace both read it.


selector?

optional selector?: ResourceSelector;

Defined in: shared/access/types.ts:151

On this page