Appearance
JSON-DAT: permissionSet.rules
JSONB element of: permissionSet.rules
The column holds an array of permission rule objects.
Data Attributes Table
| Attribute Name | Description | Data Type | Default Value | Required (= Nullable) | Unique | Format | Validations | Index | Example |
|---|---|---|---|---|---|---|---|---|---|
| permissionCode | The permission this rule applies to (e.g. tenant.buildings.read). | String | - | Yes | No | dot.separated code | Non-empty | - | tenant.buildings.read |
| effect | Whether this rule grants or removes the permission. A deny always wins over an allow for the same code within one Permission Set. | Enum (PermissionRuleEffect) | - | Yes | No | - | One of: allow, deny | - | allow |
| scope | How broadly the rule applies. Currently only all (every record the permission code covers) — own and resource were both considered and dropped; see PermissionRuleScope. | Enum (PermissionRuleScope) | - | Yes | No | - | One of: all | - | all |