Role
The kind of capability being granted: WRITER may publish under a path, AGENT may act as the issuing account; no other role exists in data.

· one of 2 variants:

A role is the coarse kind of authority a capability grants. Hypermedia has no fine-grained permission lists. Exactly two roles exist in the network today.

    WRITER may publish Refs at the capability's path and every path beneath it: create, update, fork, move, delete and redirect documents there. A WRITER at the space root also counts as a collaborator for reading private content over HTTP. A WRITER on a sub-path does not. For private peer sync, a WRITER at any path counts.

    AGENT is full delegation of the issuer's key. It must have an empty path. An AGENT does everything the issuer can do in the issuer's space, signs the issuer's profile, may alias itself to the issuer, and inherits the issuer's direct grants in other spaces for one hop. Devices and browser sessions are linked to an account this way. The name predates AI agents, and Seed Agents use it too.

The values are upper-case for compatibility with the old protobuf enum names. Permanent data uses PascalCase everywhere else. An EDITOR role is reserved as a comment in the API definition and does not exist. Team designs that speak of owners, admins, members or subscribers describe product features, and none of them is a role in data. See Permissions for what each role allows and where.

See also

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime