resourceGrants
Identities currently assigned to a resource (who has access). Non-revoked assignments only. Requires provisioning.read.
resourceGrants(
resourceId: ID!
): [ResourceGrant!]!
Arguments
resourceGrants.resourceId ● ID! non-null scalar
Type
ResourceGrant object
One identity's current (non-revoked) assignment to a resource — a "who has access to resource X" row.
Read AssignedResource.grants for the observed live Grants of that assignment with admin provenance by default, or grants(reviewable: true) to apply review exclusions for the review projection; both require review.item.read.