# fyi.opensocial.permissions

> Published by [lexicons.opensocial.fyi](https://lexicon.garden/identity/did:plc:2gqnilpksz2e7faj3bwvo6qc)

✓ This is the authoritative definition for this NSID.

## Links

- [View on Lexicon Garden](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.permissions)
- [Documentation](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.permissions/docs)
- [Examples](https://lexicon.garden/lexicon/did:plc:2gqnilpksz2e7faj3bwvo6qc/fyi.opensocial.permissions/examples)

## Definitions

### `fyi.opensocial.permissions#action`

**Type**: `string`

**Known Values**:
- `mod.read`
- `mod.resolve`
- `label`
- `takedown`
- `invite`
- `admit`
- `eject`
- `role.assign`
- `space.create`
- `space.configure`
- `space.delete`
- `group.configure`

### `fyi.opensocial.permissions#binding`

**Type**: `object`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `actions` | `array` | Yes |  |
| `assignable` | `array` | No | For role.assign and eject: the roles this role may grant, revoke, or eject. Absent means none. |
| `repoCollections` | `array` | No | Collections a holder of this role may write in the group's public repo when acting as the group (signed in as it through an app). '*' for any. Absent means any for a role that holds group.configure, and none otherwise. Writes into the group's spaces are governed by each space's access record instead. |
| `role` | `string` | Yes | A role id: the record key of a fyi.opensocial.role record. |

### `fyi.opensocial.permissions`

**Type**: `record`

The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.

**Key**: `literal:self`

| Property | Type | Required | Description |
|----------|------|----------|-------------|
| `bindings` | `array` | Yes |  |
| `createdAt` | `string` (datetime) | Yes |  |

## Raw Schema

```json
{
  "$type": "com.atproto.lexicon.schema",
  "defs": {
    "action": {
      "knownValues": [
        "mod.read",
        "mod.resolve",
        "label",
        "takedown",
        "invite",
        "admit",
        "eject",
        "role.assign",
        "space.create",
        "space.configure",
        "space.delete",
        "group.configure"
      ],
      "type": "string"
    },
    "binding": {
      "properties": {
        "actions": {
          "items": {
            "ref": "#action",
            "type": "ref"
          },
          "type": "array"
        },
        "assignable": {
          "description": "For role.assign and eject: the roles this role may grant, revoke, or eject. Absent means none.",
          "items": {
            "description": "A role id: the record key of a fyi.opensocial.role record.",
            "maxLength": 64,
            "type": "string"
          },
          "type": "array"
        },
        "repoCollections": {
          "description": "Collections a holder of this role may write in the group's public repo when acting as the group (signed in as it through an app). '*' for any. Absent means any for a role that holds group.configure, and none otherwise. Writes into the group's spaces are governed by each space's access record instead.",
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "role": {
          "description": "A role id: the record key of a fyi.opensocial.role record.",
          "maxLength": 64,
          "type": "string"
        }
      },
      "required": [
        "role",
        "actions"
      ],
      "type": "object"
    },
    "main": {
      "description": "The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.",
      "key": "literal:self",
      "record": {
        "properties": {
          "bindings": {
            "items": {
              "ref": "#binding",
              "type": "ref"
            },
            "type": "array"
          },
          "createdAt": {
            "format": "datetime",
            "type": "string"
          }
        },
        "required": [
          "bindings",
          "createdAt"
        ],
        "type": "object"
      },
      "type": "record"
    }
  },
  "id": "fyi.opensocial.permissions",
  "lexicon": 1
}
```
