Govern
Role-based access control
Access is decided in three layers: what a role may do, which parts of the schema it may do it to, and which individual records it can see. Every layer applies on the API and in the UI alike, and an agent session inherits the whole stack from the person who authorized it.
The three layers
Named permissions
Each module publishes the actions it allows — create entities, delete entities, edit roles, and so on — and a role is assembled from that catalog. Whether a role may delete a record at all is settled here.
Resource restrictions
Point a role at one template or one attribute and set how far it reaches: deny, view, edit, or full. This is the exception layer, for when a role needs different treatment on a specific part of the schema.
Row-level entity scopes
Conditions on attribute values decide which individual records a role sees, using eq, neq, gt, lt, like, not-like, empty, and not-empty. A contractor role reaches the sites assigned to it and nothing else.
The four access levels
Levels are ordered full, edit, view, deny. A level satisfies any requirement at or below its own rank, with one exception: a denial satisfies nothing at all.
Satisfies nothing
A denial is absolute. It never satisfies a requirement, whatever else the role carries.
Read
Satisfied by any positive level. The floor for cross-functional teams and reviewers.
Read and write
Satisfied by edit or full. Enough to change values on the resource it covers.
Read, write, and administer
The only level that satisfies a full requirement, and the top of the hierarchy.
Scopes apply where the query is built
A role's row-level conditions are compiled into the query that fetches the records, so the restriction holds on every read path the API serves: browsing, search, exports, and an agent session alike.
The same rules on the API
A programmatic access token is issued for the authenticated user inside the active project, and it inherits that user's role permissions and scopes. A script cannot reach past what the person who created its token can reach.
Tokens carry an omni_ prefix and a required expiry date. The secret is returned once
at creation and cannot be recovered afterwards. A lost token is
replaced with a new one.