Each service has a set of permissions defined. When a service access another service, the user needs those permissions too. Each permission can come in the flavors READ, WRITE, and DELETE. If you give a user a permission in a service, you should give them all the permissions in the other services that one permission depends on. This page documents those permissions and their dependencies to make this easier:
All provisioner endpoints are permissioned as system permissions. The provisioner provides no other permissions, and no service depends on provisioner permissions.
Identity does not depend on other services.
flavors: READ, WRITE
flavors: READ, WRITE, DELETE
A user's ability to change their own password, and to permit services to act on their behalf. This permission cannot be withdrawn.
flavors: READ, WRITE, DELETE
A service's ability to request permissions to other services
flavors: READ, WRITE
All rhythm endpoints have system permissions. Creating a beat for a tenant requires the identity__v1__app_self permission.
Accounting does not depend on other services.
flavors: READ, WRITE, DELETE
flavors: READ, WRITE, DELETE
flavors: READ, WRITE
flavors: READ, WRITE
flavors: READ
flavors: READ
The office service relies on the user ids from identity, but does not access any other services. Office is not dependent on any other permissions.
flavors: READ, WRITE, DELETE
flavors: READ, WRITE, DELETE
The ability for an employee to edit their own details including contact details.
flavors: READ, WRITE, DELETE
The customer service is not dependent on any other services.
flavors: READ, WRITE
flavors: READ, WRITE, DELETE
flavors: READ, WRITE, DELETE
flavors: READ, WRITE
The ability to add custom properties for customers.
flavors: READ, WRITE, DELETE
Permission modeling of the group service is incomplete.
Depends on the services rhythm, accounting, and customer. The dependency to rhythm has no influence on configurable permissions.
flavors: READ, WRITE, DELETE
deposit__V1__definition.READ
portfolio__v1_definitions.WRITE
flavors: READ, WRITE
deposit__v1__instance.READ
deposit__v1__instance.WRITE
Depends on the services rhythm, accounting, and customer. The dependency to rhythm has no influence on configurable permissions.
flavors: READ, WRITE
portfolio__v1__products__enable.WRITE requires
portfolio__v1__products__enable.READ requires
portfolio__v1__products__lossprv
flavors: READ, WRITE
flavors: READ, WRITE, DELETE
flavors: READ, WRITE
portfolio__v1__case.WRITE dependent on:
flavors: READ, WRITE, DELETE
teller__v1__management.READ
teller__v1__management.WRITE
flavors: READ, WRITE
teller__v1__operation.WRITE
flavors: READ, WRITE
cheques__v1_management.WRITE
flavors: READ, WRITE
cheques__v1__transaction.READ
flavors: READ, WRITE, DELETE
payroll__v1__configuration.WRITE
payroll__v1__distribution.WRITE
Reporting does not depend on other services.
flavors: READ, WRITE