Skip to content

Define client roles and capability permissions #20

Description

@ian-pascoe

Question

How do Accounts, Organization memberships, Host Administrator and Organization Operator permissions, and Organization-scoped Roles assigned to Client Principals compose; which permissions can target Host Source Definitions and their Organization-scoped Capability Source instances, database-defined and project-defined Capability Sources, Source Items, protocol actions, project source declaration, outbound hosts and Source Kinds, Project Configuration Snapshots, Project Contexts, host-owned, Organization-owned, and Account-owned Source Credentials, Secret Requirements, and Secret Grants; how do defaults and deny rules compose; and how do policy or membership changes affect discovery, invocation, context renewal, Surface Revisions, audit evidence, automated clients, and the local stdio principal?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions