Reference
governance.role_grant
domain: governance
Assigns a USER a ROLE within a tenant (scoped RBAC). A tenant admin grants it; it is the artifact of 'this person may act in this role'. The desktop unions a user's granted roles with their identity roles to decide which role-scoped apps they see; the host + kernel enforce what each role may DO.
| Field | Type | Required | Description |
|---|---|---|---|
schema | โ | โ | |
id | string | โ | ds:<tenant>:role_grant/<role>--<user-sub> |
tenant | string | โ | |
subject | string | โ | the user, e.g. user://kmc/anita |
role | string | โ | |
granted_by | string | ||
granted_at | string |