entities.rules
Per-operation authorization rules — CEL, compiled into a SQL predicate.
Guide: Access rules
The entities block spans these pages: entities · entities · fields · entities · computed & rollups · entities · rules · entities · hooks · entities · indexes.
entities.<name>.rules
Section titled “entities.<name>.rules”Per-operation authorization rules — CEL, compiled into a SQL predicate. Missing operation = deny (secure-by-default).
- Type:
object - Required: no
entities.<name>.rules.list
Section titled “entities.<name>.rules.list”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no
entities.<name>.rules.get
Section titled “entities.<name>.rules.get”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no
entities.<name>.rules.create
Section titled “entities.<name>.rules.create”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no
entities.<name>.rules.update
Section titled “entities.<name>.rules.update”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no
entities.<name>.rules.delete
Section titled “entities.<name>.rules.delete”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no