Skip to content

Role conditions

A statement’s conditions narrow what it matches. Each connector offers the subset that applies to its actions; the role editor shows only those. On a deny statement a condition that can never be satisfied is refused at save, because the guardrail would silently never fire.

Condition Type Choices Meaning
channel_ids list Only these Slack channel ids.
collections list Only these vector collections.
file_extensions list Only objects with these extensions.
indices list Only these search indices.
methods enum_list GET, HEAD, POST, PUT, PATCH, DELETE Only requests with these methods.
object_ids list Only these object ids.
object_types list Only these object types (e.g. ticket, issue).
orgs list Only repositories in these orgs.
path_prefixes list Only paths starting with one of these. Ignored when a request has no path.
projects list Only these GitLab project ids.
repos list Only these repositories (name only).
require_where bool Only UPDATE or DELETE statements that have a WHERE clause.
risk_levels enum_list low, medium, high Only requests InterLock classifies at these risk levels.
workflows list Only these workflow files.