Kaizen
Browse modulesAccessaccess/sharedInterfaces

Interface: Grant

Defined in: shared/access/types.ts:87

An ALLOW binding of subject → role within a scope, optionally narrowed by a selector (indexable fast path) and/or an ABAC condition (ConditionLogicNode, for non-indexable / cross-cutting rules). Allow-only in v1. Binds to role IDENTITY, not a frozen version.

Properties

condition?

optional condition?: ConditionLogicNode;

Defined in: shared/access/types.ts:93


effectiveEnd?

optional effectiveEnd?: string | null;

Defined in: shared/access/types.ts:95


effectiveStart?

optional effectiveStart?: string | null;

Defined in: shared/access/types.ts:94


id

id: string;

Defined in: shared/access/types.ts:88


roleId

roleId: string;

Defined in: shared/access/types.ts:91


scope

scope: GrantScope;

Defined in: shared/access/types.ts:89


selector?

optional selector?: ResourceSelector;

Defined in: shared/access/types.ts:92


subject

subject: Subject;

Defined in: shared/access/types.ts:90

On this page