Interface: DecisionTraceEntry
Defined in: shared/access/types.ts:112
One entry in a decision trace — every grant the kernel consulted.
Properties
conditionPassed?
optional conditionPassed?: boolean;Defined in: shared/access/types.ts:124
conditionResults?
optional conditionResults?: ConditionResult[];Defined in: shared/access/types.ts:125
grantId
grantId: string;Defined in: shared/access/types.ts:113
matched
matched: boolean;Defined in: shared/access/types.ts:120
Did this grant authorize the action?
permission
permission: `${string}.${string}`;Defined in: shared/access/types.ts:116
reason
reason: string;Defined in: shared/access/types.ts:122
Why it did/didn't, for human-readable explanation.
roleId
roleId: string;Defined in: shared/access/types.ts:114
roleIdentifier?
optional roleIdentifier?: string;Defined in: shared/access/types.ts:115
scopeKey
scopeKey: string;Defined in: shared/access/types.ts:118
scopeKeyOf of the consulted grant's own CompiledGrant.scope.
selectorMatched?
optional selectorMatched?: boolean;Defined in: shared/access/types.ts:123