permissions

Read-only permission matrix

FieldValue
Trust classinteractive
Implementation statusimplemented_native
Renderernative block
Key prop (production schema)policy_id
Key prop (protocol fixture)policyId
Toolsfilter
Package version1.0.0
Package digestsha256:4723e1b392af90ca6866c823f5273b33bdb47bfbf077234ddcf70bed8936e5c7

Install

docsloth component add @docsloth/permissions@1.0.0

Live package: sha256:4723e1b392af90ca6866c823f5273b33bdb47bfbf077234ddcf70bed8936e5c7 with 2 file digest(s); the catalog entry is generated from the built package, not a placeholder.

Props

The prop schema is normative in packages/contracts/component-props/permissions.schema.json.

PropTypeRequiredConstraints
titlestringnomaxLength: 160
policy_idstringyesformat: uuid
rolesarray<string>yes
actionsarray<string>yes
matrixarray<object>yes

Example props generated from this schema:

{
  "title": "example-title",
  "policy_id": "00000000-0000-4000-8000-000000000000",
  "roles": [
    "example-roles"
  ],
  "actions": [
    "example-actions"
  ],
  "matrix": [
    {
      "key": "example-key",
      "cells": [
        "example-cells"
      ]
    }
  ]
}

Required props: policy_id, roles, actions, matrix.

Example

Example document IR (the block the renderer consumes):

{
  "type": "permissions",
  "props": {
    "title": "example-title",
    "policy_id": "00000000-0000-4000-8000-000000000000",
    "roles": [
      "example-roles"
    ],
    "actions": [
      "example-actions"
    ],
    "matrix": [
      {
        "key": "example-key",
        "cells": [
          "example-cells"
        ]
      }
    ]
  }
}

Renderer HTML (entities decoded and wrapped for display):

<section class="ds-block ds-permissions" data-component="permissions" aria-labelledby="b-title">
<h3 class="ds-block-title" id="b-title">example-title</h3>
<table class="ds-table">
<caption>Permissions by role</caption>
<thead>
<tr>
<th scope="col">Action</th>
<th scope="col">example-roles</th>
</tr>
</thead>
<tbody>
<tr>
<th scope="row">example-key</th>
<td>example-cells</td>
</tr>
</tbody>
</table>
<dl class="ds-facts">
<div>
<dt>Actions without a row</dt>
<dd>
<code>example-actions</code>
</dd>
</div>
</dl>
</section>

Preview (interface-only; the markup above is the same output):

example-title

Permissions by role
Actionexample-roles
example-keyexample-cells
Actions without a row
example-actions

The renderer resolves this component as a native block; the preview above is its real HTML output, and Markdown parity for native blocks is covered by the renderer test suite.

Specification

Generated from packages/contracts/component-specs/permissions.md.

Contract

Production props are normative in ../contracts/component-props/permissions.schema.json. The corresponding component-fixtures manifest is only a minimal protocol fixture; use the production props schema when building the published package. The packaged artifact ships exactly its generated component-package.json manifest plus props.schema.json (the production props schema, copied byte-for-byte) and spec.md (this spec, copied byte-for-byte); it contains no executable payload, fallback implementation, Storybook, test suite, SSR harness or README. Rendering behavior and the acceptance cases below belong to the renderer and the repository tests, not to the package. Installation pins the package version and the digest of every shipped byte.

Intended behavior

Read-only approved role/action matrix, distinguishes docs visibility from software privileges.

Failure and fallback

Unknown permission cannot default allow.

Required acceptance cases

Matrix matches policy fixture and accessible table. Also test empty data, loading, denied access, browser without JS, mobile 360px, keyboard navigation, dark mode and an explicit constrained agent tool call. The server independently authorizes capability requests; a package manifest cannot grant authority.

Data and maintenance

Data bindings resolve from a specific publication/release vector and permitted fact/evidence graph. Configuration edits create versioned component patches. Update invalidation uses dependency IDs, never indiscriminate whole-page regeneration. Human-owned props survive automatic updates unless invalidated with an explicit conflict. Missing optional resources leave an honest inert/readable fallback, not a broken page or fake success.

Cost and tools

Pure/local interaction must never invoke a model by accident. Any model, remote query or executor call must reserve approved budget before dispatch. Public visitors do not inherit owner resources. The component may call only named tools in its signed manifest with valid typed inputs. A cancelled job stops polling and closes resources. No component gets platform administration, raw credentials or an unlimited execution loop.

Package manifest

Protocol fixture: packages/contracts/component-fixtures/permissions.json.

FieldValue
Name@docsloth/permissions
Version1.0.0
Protocol1.x
LicenseApache-2.0
Runtimereact
Entrydist/index.js
Recording policymasked
Fallbackhtml, markdown, json
Network hostsnone
Production writeno
Max runtime seconds0
Integrityall zeros (protocol fixture placeholder)
ToolEffectConfirmationInput
filterreadnovalue

Sources

SourcePath
Component pagehttps://registry.docsloth.dev/components/permissions.html
Markdown twinhttps://registry.docsloth.dev/docs/permissions.md
LLM indexhttps://registry.docsloth.dev/llms.txt
Specificationpackages/contracts/component-specs/permissions.md
Prop schemapackages/contracts/component-props/permissions.schema.json
Protocol fixturepackages/contracts/component-fixtures/permissions.json
Catalogpackages/contracts/component-catalog.json