Skip to content

Roles

ModeratorIM resolves what a user may do through a chain:

user → groups → roles → permissions
  • A role is a named bundle of permission grants (see Permissions).
  • A group is the only carrier of roles — a group holds one or more roles.
  • A user belongs to one or more groups, and so inherits the roles those groups carry, and through them the permissions.

A user’s effective grants are the union of the permissions from every role of every group they belong to. The authorization service resolves this chain when deciding a request.

A super_user bypasses the whole chain — they hold every permission and every role without enumerating grants. Use it sparingly; ordinary access should flow through groups and roles.

Assigning roles to groups rather than directly to users keeps membership and capability separate: you manage who is in a group independently of what that group can do. Moving a user between groups changes their capabilities without editing roles, and changing a group’s roles updates every member at once.

Roles and their permission grants are created and adjusted through the authorization service (an app that manages permissions receives an authz handle on its request context, so it never imports the service directly). Assigning grants validates each one is a well-formed permission or wildcard before it is stored.