Skip to main content
Access rules decide who can read and change your tables. Business operations and approvals have their own permissions, which Bijection stores for each user. A user holds none of them until they are granted, and a deployment administrator manages them with bijection permissions.

Permissions

A user is named by their token identifier, the tokenIdentifier field of their identity: the issuer and subject joined by |, as in https://auth.example.com|user_123. See Auth in Functions. It is not a JWT.

Granting and revoking

true activates the permission and false revokes it.
Setting a permission requires administrator credentials for the deployment with permission to deploy to it.
set is sent once and not retried. If the command fails without confirming the change, check the permission with bijection permissions status before trying again.

Checking a permission

Both commands print the permission as the deployment stores it:
Checking a permission requires administrator credentials for the deployment with permission to view its data.

Options

Each permission names exactly one kind of resource: --operation for read, invoke and preview, and --approval-resource for approve and use_approval. Identifiers must be non-empty, at most 1024 bytes and free of control characters.