WS

Grants

The access-policy matrix — which role may do what to each relation, served by the system.grants table. The model is default-deny: any (relation, role, verb) not listed here is denied. Operators — the non-authenticated control plane — bypass policies entirely; these grants govern end-user (authenticated) access only.

Invocation

  • readInvoke once — a one-shot SELECT.
  • subscribeInvoke as a live STREAM — continuous deltas.

Visibility

  • definitionSee the relation's SQL body / DDL — the visibility control, separate from invoking it.

Write (not yet wired)

  • insertWrite rows — not yet wired into engine enforcement.
  • deleteDelete rows — not yet wired into engine enforcement.

Access policies

…livesystem.grants · live
Relation / roleRelation UUIDGranted verbs

Command Palette

Search for a command to run...