snippet

Access rules

Tier 2productdesignengineeringA person checks this

Define permissions and row access in one place. Use them to design gated navigation, empty lists, and disabled actions.

Add to your project
Add "Access rules" from ntent to this repo.

Fetch https://ntent.app/r/f/access as plain text. Merge it into contract.json, at the top level, after actors, without disturbing what is already there.

Then check it: Point at a new route and ask which matrix row permits it. If the answer needs a conversation, the row is missing.

Reads https://ntent.app/r/f/access

Read the code
contract.json · at the top level, after actors
17 lines
"access": {
  "tenancy": {
    "scope_entity": "customer",
    "rule": "Every invoice, subscription and payment row carries customer_id. A customer actor reads only rows whose customer_id is their own. There is no cross-customer read at any layer.",
    "staff_exception": "finance_admin reads across all customers. Every such read is written to the audit log with the actor and the row id."
  },
  "matrix": [
    {
      "actor": "finance_admin",
      "entity": "invoice",
      "can": ["read", "create", "void"],
      "cannot": ["update"],
      "why": "BR-014. An issued invoice is the legal record, so correcting one means voiding and reissuing."
    },
    { "actor": "customer", "entity": "invoice", "can": ["read", "pay"], "scope": "own" }
  ]
}

Success check: Point at a new route and ask which matrix row permits it. If the answer needs a conversation, the row is missing.

Included in