Skip to main content

resourceGrants

Identities currently assigned to a resource (who has access). Non-revoked assignments only. Requires provisioning.read.

resourceGrants(
resourceId: ID!
): [ResourceGrant!]!

Arguments​

resourceGrants.resourceId ● ID! non-null scalar​

Type​

ResourceGrant object​

One identity's current (non-revoked) assignment to a resource — a "who has access to resource X" row. Read AssignedResource.grants for the observed live Grants of that assignment with admin provenance by default, or grants(reviewable: true) to apply review exclusions for the review projection; both require review.item.read.