Skip to content
โ—‡ AirawatOS Developer
๐Ÿšง Under development โ€” this portal is being built track by track. Content will keep growing, and some sections are still placeholders.

Reference

โ† Schema catalogue

governance.role_grant

domain: governance

Assigns a USER a ROLE within a tenant (scoped RBAC). A tenant admin grants it; it is the artifact of 'this person may act in this role'. The desktop unions a user's granted roles with their identity roles to decide which role-scoped apps they see; the host + kernel enforce what each role may DO.

FieldTypeRequiredDescription
schemaโ€”โœ“
idstringโœ“ds:<tenant>:role_grant/<role>--<user-sub>
tenantstringโœ“
subjectstringโœ“the user, e.g. user://kmc/anita
rolestringโœ“
granted_bystring
granted_atstring