Kaizen
Browse modulesAccessaccess/sharedInterfaces

Interface: PermissionSnapshot

Defined in: shared/access/types.ts:162

The full server-only policy for a subject, compiled once per request. NEVER sent to the browser — it would leak role names, org structure, and policy logic. The client gets the minimized CapabilitySnapshot instead.

Properties

conditionsTable?

optional conditionsTable?: Record<string, Condition>;

Defined in: shared/access/types.ts:182

Conditions table keyed by Conditions.id, inlined from the current ConditionVersions. Threaded into the ABAC walker; built server-side (requires Prisma row shapes), so it is optional on the shared type.


grants

grants: CompiledGrant[];

Defined in: shared/access/types.ts:170


roleVersionIds

roleVersionIds: string[];

Defined in: shared/access/types.ts:176

Role version ids that contributed to this snapshot. (v1 compiles fresh per request; a v2 cache would fold these into its key — see the deferred snapshot cache in docs/rbac/design.md.)


scopes

scopes: GrantScope[];

Defined in: shared/access/types.ts:169

The scope chain this snapshot was compiled over, [0] being the target of the check — see scopeChain. The kernel ORs across the resulting grants and never reads scope itself.


subject

subject: Subject;

Defined in: shared/access/types.ts:163

On this page