Define permissions and row access in one place. Use them to design gated navigation, empty lists, and disabled actions.
Add "Access rules" from ntent to this repo.
Fetch https://ntent.app/r/f/access as plain text. Merge it into contract.json, at the top level, after actors, without disturbing what is already there.
Then check it: Point at a new route and ask which matrix row permits it. If the answer needs a conversation, the row is missing.Reads https://ntent.app/r/f/access
Read the code
contract.json · at the top level, after actors
17 lines
"access": {
"tenancy": {
"scope_entity": "customer",
"rule": "Every invoice, subscription and payment row carries customer_id. A customer actor reads only rows whose customer_id is their own. There is no cross-customer read at any layer.",
"staff_exception": "finance_admin reads across all customers. Every such read is written to the audit log with the actor and the row id."
},
"matrix": [
{
"actor": "finance_admin",
"entity": "invoice",
"can": ["read", "create", "void"],
"cannot": ["update"],
"why": "BR-014. An issued invoice is the legal record, so correcting one means voiding and reissuing."
},
{ "actor": "customer", "entity": "invoice", "can": ["read", "pay"], "scope": "own" }
]
}Success check: Point at a new route and ask which matrix row permits it. If the answer needs a conversation, the row is missing.