WS

Operator Grants

The database-operator access-policy matrix — which operator role (a system.users role) may do what to each relation, served by the system.operator_grants table (ADR-043). This is a separate access domain from Application Grants: the same relation and the same role name carry independent grants here and there — granting to an operator role never affects the end-user grants, and vice versa. Still default-deny; role 'admin' bypasses everything.

Invocation

  • readInvoke once — a one-shot SELECT.
  • subscribeInvoke as a live STREAM — continuous deltas.

Visibility

  • definitionSee the relation's SQL body / DDL — the visibility control, separate from invoking it.

Write (not yet wired)

  • insertWrite rows — not yet wired into engine enforcement.
  • deleteDelete rows — not yet wired into engine enforcement.

Operator access policies

…livesystem.operator_grants · live
Relation / operator roleRelation UUIDGranted verbs

Command Palette

Search for a command to run...