Interface: CompiledGrant
Defined in: shared/access/types.ts:140
A grant compiled for in-memory evaluation: the grant joined with the flat
permission set of its (current) role version. This is what the kernel walks
ā no DB access happens inside evaluateAccess.
Properties
condition?
optional condition?: ConditionLogicNode;Defined in: shared/access/types.ts:152
effectiveEnd?
optional effectiveEnd?: string | null;Defined in: shared/access/types.ts:154
effectiveStart?
optional effectiveStart?: string | null;Defined in: shared/access/types.ts:153
grantId
grantId: string;Defined in: shared/access/types.ts:141
permissions
permissions: `${string}.${string}`[];Defined in: shared/access/types.ts:150
roleId
roleId: string;Defined in: shared/access/types.ts:142
roleIdentifier
roleIdentifier: string;Defined in: shared/access/types.ts:143
scope
scope: GrantScope;Defined in: shared/access/types.ts:149
The scope this grant was GRANTED IN ā per row, never the scope of the
check. An organization-scoped check carries platform rows here (see
scopeChain); footing derivation and the decision trace both read it.
selector?
optional selector?: ResourceSelector;Defined in: shared/access/types.ts:151