Governance

ReBAC access model — define relations, author policies, and configure promotion authority.

NL Author — policy
⌘↵ to send

Current access model: Casbin RBAC (application-level) + siloed dg_v2 RLS (not joined to Casbin). contractor_access_grants (M147) is the only existing ReBAC-like tuple. This surface is the design target for the full ReBAC join.

RelationSubject TypeObject TypeAccess Implication
OWNSPartyPropertyAssert facts; full read on owned properties
MANAGESPartyPropertyRead and assert operational facts
OCCUPIESPartyPropertyRead occupancy and lease facts for their space
OPERATESPartyPropertyVendor-level read on operational data
LENDS_TOPartyPartyRead financial covenants and loan facts
EMPLOYSPartyPartyHR-scoped read