> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bijection.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Operation and Approval Permissions

> Grant and inspect a user's permissions on operations and approvals with bijection permissions

[Access rules](/access/overview) decide who can read and change your tables.
Business [operations](/operations/overview) and approvals have their own
permissions, which Bijection stores for each user. A user holds none of them
until they are granted, and a deployment administrator manages them with
`bijection permissions`.

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
bijection permissions set 'https://auth.example.com|user_123' invoke true --operation invoices:send
```

## Permissions

| Permission | Resource | Lets the user |
| - | - | - |
| `invoke` | An operation, with `--operation` | Invoke the operation |
| `preview` | An operation, with `--operation` | Preview the operation without accepting it |
| `read` | An operation, with `--operation` | Read the results of the operation's invocations |
| `approve` | An approval resource, with `--approval-resource` | Issue approvals for that resource |
| `use_approval` | An approval resource, with `--approval-resource` | Use an approval for that resource as its beneficiary |

A user is named by their token identifier, the `tokenIdentifier` field of
their identity: the issuer and subject joined by `|`, as in
`https://auth.example.com|user_123`. See
[Auth in Functions](/auth/functions-auth#user-identity-fields). It is not a
JWT.

## Granting and revoking

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
bijection permissions set <token-identifier> <permission> <true|false> [options]
```

`true` activates the permission and `false` revokes it.

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
# Let a user invoke invoices:send
bijection permissions set 'https://auth.example.com|user_123' invoke true \
  --operation invoices:send

# Revoke it
bijection permissions set 'https://auth.example.com|user_123' invoke false \
  --operation invoices:send

# An operation of an installed component
bijection permissions set 'https://auth.example.com|user_123' invoke true \
  --operation orders:cancel --component billing

# Let a user issue approvals for a declared approval resource
bijection permissions set 'https://auth.example.com|user_123' approve true \
  --approval-resource refunds
```

Setting a permission requires administrator credentials for the deployment
with permission to deploy to it.

<Note>
  `set` is sent once and not retried. If the command fails without confirming
  the change, check the permission with `bijection permissions status` before
  trying again.
</Note>

## Checking a permission

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
bijection permissions status <token-identifier> <permission> [options]
```

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
bijection permissions status 'https://auth.example.com|user_123' invoke \
  --operation invoices:send
```

Both commands print the permission as the deployment stores it:

```json theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
{
  "principal": "user:https://auth.example.com|user_123",
  "resource": "operation/root/invoices.js:send",
  "permission": "invoke",
  "is_active": true
}
```

Checking a permission requires administrator credentials for the deployment
with permission to view its data.

## Options

| Option | Description |
| - | - |
| `--operation <module:export>` | The operation, for `read`, `invoke` and `preview`. |
| `--component <path>` | The installed component the operation belongs to. Defaults to your app's root. Only with `--operation`. |
| `--approval-resource <resource>` | The approval resource, for `approve` and `use_approval`. |
| `--prod` | Use the project's default production deployment. |
| `--deployment <deployment>` | Use a specific deployment: a deployment name, a reference such as `staging`, `dev`, `prod` or `local`. |

Each permission names exactly one kind of resource: `--operation` for `read`,
`invoke` and `preview`, and `--approval-resource` for `approve` and
`use_approval`. Identifiers must be non-empty, at most 1024 bytes and free of
control characters.
