AUTHORIZATION AND POLICY · LAB
Build roles, assign them, and work out effective permissions
Give Cora two roles, predict her effective permissions as a union, confirm the server's answer, and see that groups and roles stay separate here.
Partly readyUses your lab tenant
The lesson
Builds on: Checking access to each object.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.
- G45 Management role assignments scoped to part of a tenant or assigned to groups
Your progress
Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.
Sign in to start this lab and check your progress. Log in or create an account.
Create the temporary group
Recorded as
tenant.groups.createsucceeded.Give Cora a second role
Recorded as
tenant.users.management_roles.assignsucceeded about[email protected].Take Help desk away from Cora again
Recorded as
tenant.users.management_roles.assignsucceeded about[email protected].Cora's directory read is refused after the removal
Recorded as
tenant.users.readrejected.
Setup
Complete Object and field checks in the tenant's own APIs first. Cora holds
Auditor; Ben holdsHelp desk.In Groups, create
lab-tmp-support-deskand add Ben and Cora.Open a private window for Cora and sign in at
$ISSUER/manage. Because she holds a management role, she needs a second step: if she has no authenticator app or passkey yet, the tenant asks her to set one up now.
Walkthrough
Assign Cora
Help deskas well, so she holdsAuditorandHelp desk. Before looking anything up, write down her effective permissions: the union of both roles.
Why it matters: assignments only ever add. Nothing in one role can take away what the other grants, as the lesson's effective-permissions table shows for Omar.
In Cora's window, reload
$ISSUER/manageand ask for her current grants in the DevTools console:
(await (await fetch('/api/auth/tenant/roles')).json()).permissions
Compare the list with your prediction.
Why it matters: effective permissions are what the server computes from current assignments, on this request. Your union and its answer should match exactly.
Read an assignment as a record. In Audit, open the
tenant.users.management_roles.assignevent for Cora. Identify the principal (Cora, a tenant user, by stable ID), the role, the actor (you) and the time. Then note what the lesson's record has that this one does not: a scope and an expiry.
Why it matters: in this tenant, every management assignment covers the whole tenant. The scope is real, the tenant itself, but it is chosen by where you create the assignment, not written into it.
The scope boundary that does exist. Cora is a user of Lab Photos only. Optional: open
$ISSUER2/managein her window. Lab Mail has no account for her, and her roles mean nothing there.
Why it matters: a scope keeps "Help desk" from becoming "help desk of everything". Another tenant is outside every assignment you can make here.
Groups against roles. Open Users or Groups and look for a way to give
lab-tmp-support-deska management role. There is none.
Why it matters: here a group says who belongs together and a role says what work needs, and the two are not connected. Adding someone to a group never grants management access, so the group's managers are not quietly granting roles.
Remove
Help deskfrom Cora. In her window, run the console call from step 2 again. The list is smaller at once.
Why it matters: assignments are evaluated on each request. No session or cached copy kept the removed permissions.
Break it
Cora now holds only
Auditor, which has notenant.users.read. In her window open the Users page. The server refuses it, and Audit records the refused read.
Why it matters: no role that applies grants the permission, so default deny refuses the request. Whether the page also hides its menu item is a convenience, not the protection.
Check your work
Press Check my progress. The checks follow the group, Cora's second role, its removal and her refused directory read.
Also confirm by hand:
Your predicted union matched the
permissionslist in step 2.
Cleanup
Delete the group
lab-tmp-support-desk.Cora keeps
Auditoronly; Ben keepsHelp desk.
Missing infrastructure
G45, scoped and group-based management assignments. A management role assigned to a group, and scoped to part of the tenant, such as "users in group lab-tmp-support-desk" or "clients tagged lab", would let the full lab reproduce Omar's two assignments, the nested-group surprise and the effective-permissions table exactly. The photo library API (G3 and G22) would add library and album scopes to the same exercise.