Actions
The twelve standardized actions a role can be granted, and the methods each one guards.
A member may do whatever any of their roles allows. There are no deny rules or precedence. Actions are bound to roles in the permissions record.
| Action | Governs | Methods |
|---|---|---|
group.configure |
Edit the profile, rules, roles and permissions. | updateProfile, uploadImage, putRule, deleteRule, putRole, deleteRole |
space.create |
Create a space under the group DID. | createSpace |
space.configure |
Change a space’s config, including its access record. |
updateSpace |
space.delete |
Delete a space. | deleteSpace |
role.assign |
Grant and revoke roles, bounded by assignable. |
assignRoles |
eject |
Remove a member, bounded by assignable. |
ejectMember |
invite |
Issue invites. | createInvite, listInvites, revokeInvite |
admit |
Approve join requests. | listJoinRequests, admitMember |
mod.read |
See the moderation queue and subject histories. | listSubjects, getSubjectHistory |
mod.resolve |
Resolve or escalate a subject, add notes. | resolveSubject |
label |
Apply and negate labels, except !hide and !takedown. |
applyLabel, negateLabel |
takedown |
Apply and negate !hide and !takedown. |
applyLabel, negateLabel |
Some methods need no action at all: requestJoin, cancelJoinRequest and leaveGroup are called by a person about themselves.
assignable
role.assign and eject are bounded. A binding’s assignable list names the roles its holders may grant, revoke or eject. Without it they can do neither, even while holding the action. admitMember’s optional roles are bounded the same way.