Skip to content

Grants

A grant gives one identity one source role on one source. An identity can hold several roles on a source; their allows add up and any deny wins.

  • Add a grant from the identity’s page (or POST /api/identities/{id}/source-role-grants). It applies to the next request; the agent keeps its key.
  • Revoke it the same way. The next request is refused.
  • A grant can carry an expiry, after which it no longer counts.

Revoked grants stay in the record, so an identity’s page shows what it held and when. A role with an active grant cannot be deleted.

Legacy role labels on an identity are not grants and confer no access. They exist only for policy conditions.