Node access
The three ways a node's audience is derived, inherited from its parent, from its own grants only, or from the node its state targets.
Fetching schema…

Part of Stem. This page defines the access mode of a Node, a literal union.

The access mode says which sets are unioned to form the node's readers.

Values

value

readers of the node

use

inherit

parent's readers, plus audiences of live grants on the node or its ancestors, plus owner and admins

the default for documents and most kinds

own

audiences of live grants on the node or its ancestors, plus owner and admins

a private node under a public parent

target

readers of the node named by the kind's target pointer, plus the node's own grants, plus owner and admins

comments, and any record about another resource

Rules

The default comes from the Kind (access field) and a Node blob may override it between inherit and own; target is only valid for kinds that declare a target pointer. "Grants on its ancestors" means grants whose subject is an ancestor without exact, since a subject covers its subtree by default. The computed set is materialised per node by the indexing peer and is the only thing a read check consults; see readers. Changing a node's access mode re-evaluates its subtree.

Today (HM24)

Visibility is a two-valued field on a Ref or Comment; a private document's readers are the space owner and its root writers, and a comment copies the target's visibility once at creation and never follows it. Stem replaces the field with the mode and the grants, so a document can be shared with one person and a comment follows its document when that document's audience changes.

Example

"access": "own"

See also

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime