Typed permission catalog
This reference is generated from LeapView's canonical Go permission catalog. It describes the typed action identities, target scopes, prerequisites, delegation flags, and versioned role expansions used by the resource-authorization contract.
Catalog profile: leapview.permissions/v1. Persisted credentials and assignments must retain this profile when they adopt typed permission pairs.
Catalog presence defines stable vocabulary, not blanket runtime availability. UI selectable means a picker may offer the action only when its current authority provider supplies a matching target pair; unsupported or unqualified operations remain unavailable.
Actions
| Action | Display name | Family | Scope | Resource kinds | Check kinds | Prerequisites | Delegable | UI selectable | Description |
|---|---|---|---|---|---|---|---|---|---|
dashboard.read |
View dashboard | Dashboard | resource |
dashboard |
dashboard |
— | yes | yes | View an approved dashboard definition and shell. |
dashboard.create |
Create dashboards | Dashboard | project |
dashboard |
project |
— | yes | yes | Create a dashboard in the bound Project. |
dashboard.update |
Edit dashboard | Dashboard | resource |
dashboard |
dashboard |
— | yes | yes | Edit an existing dashboard definition. |
dashboard.delete |
Delete dashboard | Dashboard | resource |
dashboard |
dashboard |
— | no | yes | Delete or archive an existing dashboard. |
dashboard.publish |
Publish dashboard | Dashboard | resource |
dashboard |
dashboard |
— | no | yes | Publish an approved dashboard revision. |
semantic.read |
Discover metadata | Semantic consumption | resource |
semantic_model |
semantic_model |
— | yes | yes | Discover governed semantic metadata. |
semantic.query |
Build queries | Semantic consumption | resource |
semantic_model |
semantic_model |
semantic.consume |
yes | yes | Construct an arbitrary governed semantic query. |
semantic.consume |
Use governed data | Semantic consumption | resource |
semantic_model |
semantic_model |
— | yes | yes | Consume governed data from an exact SemanticModel. |
semantic.create |
Create semantic models | Development | project |
semantic_model |
project |
— | yes | yes | Create a SemanticModel definition in the bound Project. |
semantic.update |
Edit semantic model | Development | resource |
semantic_model |
semantic_model |
— | yes | yes | Update a SemanticModel definition. |
semantic.delete |
Delete semantic model | Development | resource |
semantic_model |
semantic_model |
— | no | yes | Delete a SemanticModel definition. |
source.read |
View source | Development | resource |
source |
source |
— | yes | yes | Read a Source definition. |
source.create |
Create sources | Development | project |
source |
project |
— | yes | yes | Create a Source definition in the bound Project. |
source.update |
Edit source | Development | resource |
source |
source |
— | yes | yes | Update a Source definition. |
source.delete |
Delete source | Development | resource |
source |
source |
— | no | yes | Delete a Source definition. |
model.read |
View model | Development | resource |
model |
model |
— | yes | yes | Read a Model definition. |
model.create |
Create models | Development | project |
model |
project |
— | yes | yes | Create a Model definition in the bound Project. |
model.update |
Edit model | Development | resource |
model |
model |
— | yes | yes | Update a Model definition. |
model.delete |
Delete model | Development | resource |
model |
model |
— | no | yes | Delete a Model definition. |
pipeline.read |
View pipeline | Pipeline | resource |
pipeline |
pipeline |
— | yes | yes | Read a Pipeline definition and bounded operational status. |
pipeline.create |
Create pipelines | Pipeline | project |
pipeline |
project |
— | yes | yes | Create a Pipeline in the bound Project. |
pipeline.run |
Run pipeline | Pipeline | resource |
pipeline |
pipeline |
— | yes | yes | Trigger an approved Pipeline revision. |
pipeline.update |
Edit pipeline | Pipeline | resource |
pipeline |
pipeline |
— | yes | yes | Update a Pipeline definition. |
pipeline.delete |
Delete pipeline | Pipeline | resource |
pipeline |
pipeline |
— | no | yes | Delete a Pipeline definition. |
connection.read |
View connection details | Connection | resource |
connection |
connection |
— | yes | yes | Read redacted Connection metadata. |
connection.create |
Create connections | Connection | project |
connection |
project |
— | yes | yes | Create a Connection in the bound Project. |
connection.use |
Use connection | Connection | resource |
connection |
connection |
— | yes | yes | Execute through an approved Connection binding without revealing credentials. |
connection.manage |
Manage connection | Connection | resource |
connection |
connection |
— | no | yes | Update, rotate, test, or delete a Connection. |
connection.upload |
Upload managed data | Connection | resource |
connection |
connection |
— | yes | yes | Stage and commit managed-data revisions through an exact Connection without changing its configuration or credentials. |
resource.share |
Share resource | Sharing | resource |
connection, source, model, semantic_model, pipeline, dashboard |
connection, source, model, semantic_model, pipeline, dashboard |
— | no | yes | Issue a bounded independent grant on an exact supported resource. |
delivery.read |
View releases | Delivery | project |
project |
project |
— | yes | yes | Inspect delivery plans and retained evidence. |
delivery.plan |
Plan releases | Delivery | project |
project |
project |
— | yes | yes | Persist an exact delivery plan. |
delivery.build |
Build releases | Delivery | project |
project |
project |
— | yes | yes | Build an approved delivery candidate. |
delivery.publish |
Publish releases | Delivery | project |
project |
project |
— | yes | yes | Publish a built delivery candidate. |
delivery.approve |
Approve releases | Delivery | project |
project |
project |
— | no | yes | Approve a protected delivery candidate. |
delivery.activate |
Activate releases | Delivery | project |
project |
project |
— | no | yes | Activate an approved delivery publication. |
delivery.rollback |
Roll back releases | Delivery | project |
project |
project |
— | no | yes | Rollback to eligible retained delivery evidence. |
project.settings.read |
View project settings | Project administration | project |
project |
project |
— | yes | yes | Read Project settings. |
project.settings.update |
Update project settings | Project administration | project |
project |
project |
— | no | yes | Update Project settings. |
project.access.read |
View project access | Project administration | project |
project |
project |
— | yes | yes | Inspect Project access assignments. |
project.access.manage |
Manage project access | Project administration | project |
project |
project |
— | no | yes | Maintain Project access without unbounded privilege issuance. |
project.access.delegate |
Delegate project access | Project administration | project |
project |
project |
— | no | yes | Issue authority within an explicit grant-administration envelope. |
audit.read |
View audit log | Project administration | project |
project |
project |
— | yes | yes | Read authorized Project audit evidence. |
workload.delegate |
Delegate workload | Workload delegation | resource |
pipeline |
pipeline |
— | no | yes | Issue a bounded execution grant for an exact Pipeline and workload principal. |
platform.settings.read |
View platform settings | Platform administration | instance |
— | — | — | no | yes | Read instance settings. |
platform.settings.update |
Update platform settings | Platform administration | instance |
— | — | — | no | yes | Update instance settings. |
platform.access.read |
View platform access | Platform administration | instance |
— | — | — | no | yes | Inspect instance access assignments. |
platform.access.manage |
Manage platform access | Platform administration | instance |
— | — | — | no | yes | Manage instance access assignments. |
platform.audit.read |
View platform audit log | Platform administration | instance |
— | — | — | no | yes | Read authorized instance audit evidence. |
instance.project.claim |
Claim first project | Instance bootstrap | instance |
— | — | — | no | no | Establish the first Project claim for this instance. |
Versioned role expansions
Role names are presentation presets over explicit typed actions. They do not bypass target, credential, prerequisite, or policy checks.
| Role | Profile | Actions | Description |
|---|---|---|---|
viewer |
leapview.permissions/v1 |
dashboard.read, semantic.consume |
View approved dashboards and consume explicitly scoped semantic data. |
explorer |
leapview.permissions/v1 |
dashboard.read, semantic.read, semantic.consume, semantic.query |
View approved dashboards and discover and query explicitly scoped semantic data. |
editor |
leapview.permissions/v1 |
dashboard.read, dashboard.create, dashboard.update, semantic.read, semantic.consume, semantic.query, semantic.create, semantic.update, source.read, source.create, source.update, model.read, model.create, model.update, pipeline.read, pipeline.create, pipeline.update, connection.read, connection.create, connection.use |
Explore governed data and create or update authored resources without publish, delete, share, run, or administration authority. |
project_admin |
leapview.permissions/v1 |
project.settings.read, project.settings.update, project.access.read, project.access.manage, project.access.delegate, audit.read |
Manage Project settings and access without acquiring semantic data or platform authority. |
publisher |
leapview.permissions/v1 |
dashboard.read, dashboard.publish |
Publish explicitly scoped dashboards without editing, deletion, sharing, or release authority. |
release_approver |
leapview.permissions/v1 |
delivery.read, delivery.approve |
Inspect and approve protected delivery candidates. |
release_operator |
leapview.permissions/v1 |
delivery.read, delivery.plan, delivery.build, delivery.publish, delivery.activate, delivery.rollback |
Plan, build, publish, activate, and roll back qualified releases without approval authority. |
auditor |
leapview.permissions/v1 |
project.access.read, delivery.read, audit.read |
Inspect Project access, delivery evidence, and audit events without mutation authority. |