Entities

Permission Grant

A normalised access-control entry tied to a piece of content, translated from whatever native scheme (ACL, RBAC scope, sensitivity label) the source system used.

Volume

One or more per Source Document or Knowledge Item

Retention

Superseded on each resync; historical grants not retained by default

Entity attributes6
  • permission_grant_id
  • subject_content_id
  • A chunk must inherit the most restrictive permission touching it, computed at chunking time, not the source document's average or most permissive setting.
  • Enforcement must be evaluated at query time against live claims for any source with volatile membership (e.g. project- or engagement-based access), with a bounded, documented resync SLA for index-time-baked permission metadata elsewhere.
  • Enforcement must be evaluated at query time against live claims for any source with volatile membership (e.g. project- or engagement-based access), with a bounded, documented resync SLA for index-time-baked permission metadata elsewhere.
  • Enforcement must be evaluated at query time against live claims for any source with volatile membership (e.g. project- or engagement-based access), with a bounded, documented resync SLA for index-time-baked permission metadata elsewhere.
Entity relationships2
Entity lifecycle

Not yet researched

Only the control-bearing entities were modelled for lifecycle. Defensible as a starting point, but it does leave the entity model uneven, and this is incompleteness rather than a finding.