Grants
The access-policy matrix — which role may do what to each relation, served by the system.grants table. The model is default-deny: any (relation, role, verb) not listed here is denied. Operators — the non-authenticated control plane — bypass policies entirely; these grants govern end-user (authenticated) access only.
Invocation
- readInvoke once — a one-shot SELECT.
- subscribeInvoke as a live STREAM — continuous deltas.
Visibility
- definitionSee the relation's SQL body / DDL — the visibility control, separate from invoking it.
Write (not yet wired)
- insertWrite rows — not yet wired into engine enforcement.
- deleteDelete rows — not yet wired into engine enforcement.
Access policies
…livesystem.grants · live| Relation / role | Relation UUID | Granted verbs |
|---|---|---|