Developer documentation

Scope reference

Scopes are grouped by the work they authorize. A successful scope check does not bypass current role checks for sensitive actions.

Organization context

`organizations:read`

Evaluations and outcomes

`evaluations:create`, `evaluations:read`, `evaluation_evidence:read`, `outcomes:read`, `outcomes:write`, `simulations:run`

Benefits

`benefits:read`, `benefits:write`

Policies

`policies:read`, `policies:write`

Exceptions and identifiers

`exceptions:read`, `exceptions:write`, `custom_identifiers:read`, `custom_identifiers:write`

Imports and exports

`imports:read`, `imports:write`, `exports:read`, `exports:create`

Data deletion

`data_deletions:read`, `data_deletions:write`

Monitoring

`analytics:read`, `request_logs:read`, `audit_logs:read`

Browser collection

`browser_collection:read`, `browser_collection:write`

Test tools

`test_fixtures:read`, `test_fixtures:write`

Browser observation

`observations:create`