Contracts / authorize
Contract
authorize
Whether a principal’s roles hold one named privilege on a resource. Every control-plane route calls it with exactly one privilege.
Signature
authorize({ principal, privilege, resource? })
: AuthorizeResultRules
- Roles map to privileges in one table inside the Bouncer.
- agent-owner, agent-member and requester come from data, never from a credential.
- A role check outside packages/bouncer and packages/auth fails conformance.
- A route missing from the matrix test fails conformance.
Where it appears
- Let a person or service inGatekeeper
- Connect an account (OAuth)Keymaster
- Onboard a secret (write-only)Keymaster
- Pause, kill and retireLandlord
- Set a budgetTreasurer
- Report cloud spend and computeTreasurer
- Authorize a requestBouncer
- Let an agent schedule itselfTimekeeper
- Register an agentRegistrar