A permission is a named set of resource endpoints. It is the unit roles and clients use to describe what they may call — neither ever lists endpoints directly. For the conceptual picture, see Entities.
- Permission ID — lowercase segments separated by
.or:, each starting with a letter (e.g.orders.read,orders:write:managed). - Description — a label shown in the admin console.
- Endpoints — the set of resource endpoints this permission covers, picked from one or more resources in the tenant.
Permissions reach edge’s authorization check through two different paths: