Typed permission catalog

This reference is generated from LeapView's canonical Go permission catalog. It describes the typed action identities, target scopes, prerequisites, delegation flags, and versioned role expansions used by the resource-authorization contract.

Catalog profile: leapview.permissions/v1. Persisted credentials and assignments must retain this profile when they adopt typed permission pairs.

Catalog presence defines stable vocabulary, not blanket runtime availability. UI selectable means a picker may offer the action only when its current authority provider supplies a matching target pair; unsupported or unqualified operations remain unavailable.

Actions

Action Display name Family Scope Resource kinds Check kinds Prerequisites Delegable UI selectable Description
dashboard.read View dashboard Dashboard resource dashboard dashboard — yes yes View an approved dashboard definition and shell.
dashboard.create Create dashboards Dashboard project dashboard project — yes yes Create a dashboard in the bound Project.
dashboard.update Edit dashboard Dashboard resource dashboard dashboard — yes yes Edit an existing dashboard definition.
dashboard.delete Delete dashboard Dashboard resource dashboard dashboard — no yes Delete or archive an existing dashboard.
dashboard.publish Publish dashboard Dashboard resource dashboard dashboard — no yes Publish an approved dashboard revision.
semantic.read Discover metadata Semantic consumption resource semantic_model semantic_model — yes yes Discover governed semantic metadata.
semantic.query Build queries Semantic consumption resource semantic_model semantic_model semantic.consume yes yes Construct an arbitrary governed semantic query.
semantic.consume Use governed data Semantic consumption resource semantic_model semantic_model — yes yes Consume governed data from an exact SemanticModel.
semantic.create Create semantic models Development project semantic_model project — yes yes Create a SemanticModel definition in the bound Project.
semantic.update Edit semantic model Development resource semantic_model semantic_model — yes yes Update a SemanticModel definition.
semantic.delete Delete semantic model Development resource semantic_model semantic_model — no yes Delete a SemanticModel definition.
source.read View source Development resource source source — yes yes Read a Source definition.
source.create Create sources Development project source project — yes yes Create a Source definition in the bound Project.
source.update Edit source Development resource source source — yes yes Update a Source definition.
source.delete Delete source Development resource source source — no yes Delete a Source definition.
model.read View model Development resource model model — yes yes Read a Model definition.
model.create Create models Development project model project — yes yes Create a Model definition in the bound Project.
model.update Edit model Development resource model model — yes yes Update a Model definition.
model.delete Delete model Development resource model model — no yes Delete a Model definition.
pipeline.read View pipeline Pipeline resource pipeline pipeline — yes yes Read a Pipeline definition and bounded operational status.
pipeline.create Create pipelines Pipeline project pipeline project — yes yes Create a Pipeline in the bound Project.
pipeline.run Run pipeline Pipeline resource pipeline pipeline — yes yes Trigger an approved Pipeline revision.
pipeline.update Edit pipeline Pipeline resource pipeline pipeline — yes yes Update a Pipeline definition.
pipeline.delete Delete pipeline Pipeline resource pipeline pipeline — no yes Delete a Pipeline definition.
connection.read View connection details Connection resource connection connection — yes yes Read redacted Connection metadata.
connection.create Create connections Connection project connection project — yes yes Create a Connection in the bound Project.
connection.use Use connection Connection resource connection connection — yes yes Execute through an approved Connection binding without revealing credentials.
connection.manage Manage connection Connection resource connection connection — no yes Update, rotate, test, or delete a Connection.
connection.upload Upload managed data Connection resource connection connection — yes yes Stage and commit managed-data revisions through an exact Connection without changing its configuration or credentials.
resource.share Share resource Sharing resource connection, source, model, semantic_model, pipeline, dashboard connection, source, model, semantic_model, pipeline, dashboard — no yes Issue a bounded independent grant on an exact supported resource.
delivery.read View releases Delivery project project project — yes yes Inspect delivery plans and retained evidence.
delivery.plan Plan releases Delivery project project project — yes yes Persist an exact delivery plan.
delivery.build Build releases Delivery project project project — yes yes Build an approved delivery candidate.
delivery.publish Publish releases Delivery project project project — yes yes Publish a built delivery candidate.
delivery.approve Approve releases Delivery project project project — no yes Approve a protected delivery candidate.
delivery.activate Activate releases Delivery project project project — no yes Activate an approved delivery publication.
delivery.rollback Roll back releases Delivery project project project — no yes Rollback to eligible retained delivery evidence.
project.settings.read View project settings Project administration project project project — yes yes Read Project settings.
project.settings.update Update project settings Project administration project project project — no yes Update Project settings.
project.access.read View project access Project administration project project project — yes yes Inspect Project access assignments.
project.access.manage Manage project access Project administration project project project — no yes Maintain Project access without unbounded privilege issuance.
project.access.delegate Delegate project access Project administration project project project — no yes Issue authority within an explicit grant-administration envelope.
audit.read View audit log Project administration project project project — yes yes Read authorized Project audit evidence.
workload.delegate Delegate workload Workload delegation resource pipeline pipeline — no yes Issue a bounded execution grant for an exact Pipeline and workload principal.
platform.settings.read View platform settings Platform administration instance — — — no yes Read instance settings.
platform.settings.update Update platform settings Platform administration instance — — — no yes Update instance settings.
platform.access.read View platform access Platform administration instance — — — no yes Inspect instance access assignments.
platform.access.manage Manage platform access Platform administration instance — — — no yes Manage instance access assignments.
platform.audit.read View platform audit log Platform administration instance — — — no yes Read authorized instance audit evidence.
instance.project.claim Claim first project Instance bootstrap instance — — — no no Establish the first Project claim for this instance.

Versioned role expansions

Role names are presentation presets over explicit typed actions. They do not bypass target, credential, prerequisite, or policy checks.

Role Profile Actions Description
viewer leapview.permissions/v1 dashboard.read, semantic.consume View approved dashboards and consume explicitly scoped semantic data.
explorer leapview.permissions/v1 dashboard.read, semantic.read, semantic.consume, semantic.query View approved dashboards and discover and query explicitly scoped semantic data.
editor leapview.permissions/v1 dashboard.read, dashboard.create, dashboard.update, semantic.read, semantic.consume, semantic.query, semantic.create, semantic.update, source.read, source.create, source.update, model.read, model.create, model.update, pipeline.read, pipeline.create, pipeline.update, connection.read, connection.create, connection.use Explore governed data and create or update authored resources without publish, delete, share, run, or administration authority.
project_admin leapview.permissions/v1 project.settings.read, project.settings.update, project.access.read, project.access.manage, project.access.delegate, audit.read Manage Project settings and access without acquiring semantic data or platform authority.
publisher leapview.permissions/v1 dashboard.read, dashboard.publish Publish explicitly scoped dashboards without editing, deletion, sharing, or release authority.
release_approver leapview.permissions/v1 delivery.read, delivery.approve Inspect and approve protected delivery candidates.
release_operator leapview.permissions/v1 delivery.read, delivery.plan, delivery.build, delivery.publish, delivery.activate, delivery.rollback Plan, build, publish, activate, and roll back qualified releases without approval authority.
auditor leapview.permissions/v1 project.access.read, delivery.read, audit.read Inspect Project access, delivery evidence, and audit events without mutation authority.