Access
Access decides who may do what, and where: role bindings grant a role to a user or group at a scope. Check what someone can reach, and file, approve or deny access requests.
Add bindings
Grants one role at an organization, project or agent account scope to each listed user or group, all or nothing; an existing binding comes back with `created: false`. An optional `expires_at` must be in the future and is refused on an organization scope (422). Requires permission to manage that role at the scope; returns 201 with the bindings.
Delete binding
Removes one role binding and revokes the access it gave the user or the group's members. Requires permission to manage that role at the scope. Returns 409 when it is the organization's last direct Org Owner, and 204 with no body otherwise.
Check access
Explains whether a user may perform an action on a resource: the chain of group, role and scope that allows it, or the nearest missing link. Limited to the caller's own user unless the caller is an Org Owner or Org Admin.
List members
Lists everyone holding a role at the `scope` given as `<type>:<id>`, inherited roles included, with each row labelled with its source. Group members are expanded only for a caller who may view users or manage the scope. Requires read or manage access to the scope.
List principals
Lists up to 50 users and 50 groups of the scope's organization that the caller may grant a role to there, filtered by name or email with `q`. Requires permission to manage access at the scope; the Everyone group appears only for an Org Owner or Org Admin.
Get what a user can reach
Returns everything a user's live role bindings reach, grouped by organization, project and agent account, with each binding's source. Limited to the caller's own user unless the caller is an Org Owner or Org Admin.
List requests
Lists access requests in one `box`: `pending` (open requests the caller may decide, the default), `history` (decided requests the caller may decide) or `mine` (the caller's own, in every state).
Create request
Requests a role on a project or agent account, defaulting to the least role. Returns 201 with the new request, or 200 with the identical open one; approvers with a Slack destination get a message, best effort. Returns 429 past 20 open requests.
Approve request
Approves a pending access request, granting the requester the role with an optional `expires_at`. Repeating it returns the same request unchanged; a denied request returns 409. Returns 404 for a request the caller may not decide.
Deny request
Denies a pending access request without granting anything, and returns the request. Repeating it returns the same request unchanged; an approved request returns 409, and one the caller may not decide returns 404.