Role conditions
A statement’s conditions narrow what it matches. Each connector offers the subset that applies to its actions; the role editor shows only those. On a deny statement a condition that can never be satisfied is refused at save, because the guardrail would silently never fire.
| Condition | Type | Choices | Meaning |
|---|---|---|---|
channel_ids |
list | Only these Slack channel ids. | |
collections |
list | Only these vector collections. | |
file_extensions |
list | Only objects with these extensions. | |
indices |
list | Only these search indices. | |
methods |
enum_list | GET, HEAD, POST, PUT, PATCH, DELETE |
Only requests with these methods. |
object_ids |
list | Only these object ids. | |
object_types |
list | Only these object types (e.g. ticket, issue). | |
orgs |
list | Only repositories in these orgs. | |
path_prefixes |
list | Only paths starting with one of these. Ignored when a request has no path. | |
projects |
list | Only these GitLab project ids. | |
repos |
list | Only these repositories (name only). | |
require_where |
bool | Only UPDATE or DELETE statements that have a WHERE clause. | |
risk_levels |
enum_list | low, medium, high |
Only requests InterLock classifies at these risk levels. |
workflows |
list | Only these workflow files. |