{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "Audit records emitted by lakekeeper",
  "$ref": "#/$defs/AuditRecord",
  "x-audit-emitter": {
    "name": "lakekeeper",
    "format": "1.0"
  },
  "$defs": {
    "ActionRecord": {
      "type": "object",
      "properties": {
        "action_name": {
          "type": "string",
          "x-audit-open": true,
          "description": "What was attempted. One of the action names this schema lists; a product that plugs\ninto Lakekeeper may contribute its own."
        }
      },
      "required": [
        "action_name"
      ],
      "additionalProperties": true,
      "description": "An `action` object: the wire name and the action's context fields.",
      "x-audit-kind": "part",
      "allOf": [
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "accept_moved_namespace"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "source": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The namespace path the entity is being moved from."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "apply_grants"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "deletes": {
                "type": "integer",
                "format": "int64",
                "description": "The number of entries the request asked to revoke, before deduplication."
              },
              "principals": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The distinct principals the grants are for, each prefixed by its kind, such as `user:oidc~alice` or `role:<uuid>`."
              },
              "privileges": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The distinct privilege names the request names. `[]` on a revocation that names none, which means every privilege."
              },
              "writes": {
                "type": "integer",
                "format": "int64",
                "description": "The number of entries the request asked to grant, before deduplication."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "commit"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "removed_properties": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The property keys being removed."
              },
              "target_refs": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The branch or tag references the commit targets."
              },
              "update_kinds": {
                "type": "array",
                "items": {
                  "$ref": "#/$defs/TableUpdateKind"
                },
                "description": "The kinds of update the commit contains."
              },
              "updated_properties": {
                "type": "object",
                "additionalProperties": {
                  "type": "string"
                },
                "description": "The properties being set, verbatim. The keys are the client's data."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "create_generic_table"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "base_location": {
                "type": "string",
                "description": "The storage location the client requested."
              },
              "format": {
                "type": "string",
                "description": "The table format the client requested."
              },
              "generic_table_id": {
                "type": "string",
                "description": "The generic-table id the client requested."
              },
              "name": {
                "type": "string",
                "description": "The name the client asked to create."
              },
              "properties": {
                "type": "object",
                "additionalProperties": {
                  "type": "string"
                },
                "description": "The properties the client supplied, verbatim. The keys are the client's data."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "create_namespace"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "name": {
                "type": "string",
                "description": "The name the client asked to create."
              },
              "properties": {
                "type": "object",
                "additionalProperties": {
                  "type": "string"
                },
                "description": "The properties the client supplied, verbatim. The keys are the client's data."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "create_project"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "name": {
                "type": "string",
                "description": "The name the client asked to create."
              },
              "project_id": {
                "type": "string",
                "description": "The project id the client requested."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "create_role"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "name": {
                "type": "string",
                "description": "The name the client asked to create."
              },
              "requested_provider_id": {
                "type": "string",
                "description": "The role provider the client named."
              },
              "requested_source_id": {
                "type": "string",
                "description": "The source id the client named."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "create_table"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "name": {
                "type": "string",
                "description": "The name the client asked to create."
              },
              "properties": {
                "type": "object",
                "additionalProperties": {
                  "type": "string"
                },
                "description": "The properties the client supplied, verbatim. The keys are the client's data."
              },
              "table_id": {
                "type": "string",
                "description": "The table id the client requested."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "create_tag"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "name": {
                "type": "string",
                "description": "The name the client asked to create."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "create_view"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "name": {
                "type": "string",
                "description": "The name the client asked to create."
              },
              "properties": {
                "type": "object",
                "additionalProperties": {
                  "type": "string"
                },
                "description": "The properties the client supplied, verbatim. The keys are the client's data."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "create_warehouse"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "name": {
                "type": "string",
                "description": "The name the client asked to create."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "delete"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "force": {
                "type": "boolean",
                "description": "`true` when the client asked to force the operation."
              },
              "purge": {
                "type": "boolean",
                "description": "`true` when the client asked to purge the data."
              },
              "recursive": {
                "type": "boolean",
                "description": "`true` when the client asked for a recursive delete."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "drop"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "force": {
                "type": "boolean",
                "description": "`true` when the client asked to force the operation."
              },
              "purge": {
                "type": "boolean",
                "description": "`true` when the client asked to purge the data."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "move"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "destination": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The namespace path the entity is being moved to."
              },
              "force": {
                "type": "boolean",
                "description": "`true` when the client asked to force the operation."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "read_subtree_grants"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "dry_run": {
                "type": "boolean",
                "description": "`true` when the call only reports what it would do and changes nothing."
              },
              "narrowed_privileges": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The privileges named when `privilege_scope` is `only`; `[]` when it is `every`."
              },
              "principal": {
                "type": "string",
                "description": "Whose grants are in range: `every`, or one principal prefixed by its kind, such as `user:oidc~alice` or `role:<uuid>`."
              },
              "privilege_scope": {
                "$ref": "#/$defs/PrivilegeScope",
                "description": "`every` when the request reaches every privilege a matching grant can carry, `only` when it names a set."
              },
              "resource_types": {
                "type": "array",
                "items": {
                  "$ref": "#/$defs/ResourceType"
                },
                "description": "The resource kinds the request reaches."
              },
              "root_level": {
                "$ref": "#/$defs/RootLevelGrants",
                "description": "`included` when the addressed resource's own grants are in range, `excluded` when only those beneath it are."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "revoke_subtree_grants"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "allow_partial": {
                "type": "boolean",
                "description": "`true` when the client asked a revocation to proceed despite grants it could not revoke."
              },
              "created_before": {
                "type": "string",
                "description": "RFC 3339 time: only grants created before it are in range. Absent when the request does not narrow on it."
              },
              "dry_run": {
                "type": "boolean",
                "description": "`true` when the call only reports what it would do and changes nothing."
              },
              "narrowed_privileges": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The privileges named when `privilege_scope` is `only`; `[]` when it is `every`."
              },
              "principal": {
                "type": "string",
                "description": "Whose grants are in range: `every`, or one principal prefixed by its kind, such as `user:oidc~alice` or `role:<uuid>`."
              },
              "privilege_scope": {
                "$ref": "#/$defs/PrivilegeScope",
                "description": "`every` when the request reaches every privilege a matching grant can carry, `only` when it names a set."
              },
              "privileges": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The distinct privilege names the request names. `[]` on a revocation that names none, which means every privilege."
              },
              "resource_types": {
                "type": "array",
                "items": {
                  "$ref": "#/$defs/ResourceType"
                },
                "description": "The resource kinds the request reaches."
              },
              "root_level": {
                "$ref": "#/$defs/RootLevelGrants",
                "description": "`included` when the addressed resource's own grants are in range, `excluded` when only those beneath it are."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "update_properties"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "removed_properties": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "The property keys being removed."
              },
              "updated_properties": {
                "type": "object",
                "additionalProperties": {
                  "type": "string"
                },
                "description": "The properties being set, verbatim. The keys are the client's data."
              }
            }
          }
        },
        {
          "if": {
            "properties": {
              "action_name": {
                "const": "update_source_system"
              }
            },
            "required": [
              "action_name"
            ]
          },
          "then": {
            "properties": {
              "requested_provider_id": {
                "type": "string",
                "description": "The role provider the client named."
              },
              "requested_source_id": {
                "type": "string",
                "description": "The source id the client named."
              }
            }
          }
        }
      ]
    },
    "ActorRecord": {
      "type": "object",
      "properties": {
        "actor_type": {
          "$ref": "#/$defs/ActorType",
          "description": "One of `anonymous`, `principal`, `assumed_role`, `lakekeeper_internal`."
        },
        "principal": {
          "type": "string",
          "description": "The authenticated principal. Present for `principal` and `assumed_role`."
        },
        "assumed_role": {
          "description": "The role acted as. Present for `assumed_role`; `principal` is still the human.",
          "$ref": "#/$defs/AssumedRoleRecord"
        }
      },
      "required": [
        "actor_type"
      ],
      "description": "The `actor` object: who made the request, as authentication established it.",
      "x-audit-kind": "part"
    },
    "ActorType": {
      "type": "string",
      "description": "Values of `actor_type`. A later release may add a value without a format change.",
      "x-audit-values": [
        "anonymous",
        "assumed_role",
        "lakekeeper_internal",
        "principal"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "actor_type"
    },
    "AdmissionRejectedContext": {
      "type": "object",
      "properties": {
        "gate": {
          "type": "string",
          "description": "The gate that rejected the request."
        },
        "denied_by": {
          "type": "string",
          "description": "The rule of the gate that decided, when the gate names one."
        },
        "status": {
          "type": "integer",
          "format": "uint16",
          "minimum": 0,
          "maximum": 65535,
          "description": "The HTTP status the caller received."
        },
        "error_type": {
          "type": "string",
          "description": "The error type the caller received."
        },
        "message": {
          "type": "string",
          "description": "The gate's own wording. Suppressing the error-response line takes this\nwith it, and it is what separates two rejections that share a type —\na gate failing closed on a missing precondition from the same gate\nfailing closed on an unreachable upstream."
        },
        "error_id": {
          "type": "string",
          "description": "The id the caller can quote to correlate with this record."
        }
      },
      "required": [
        "gate",
        "status",
        "error_type",
        "message",
        "error_id"
      ],
      "description": "Context for the admission-rejection audit record: which gate refused the request, on what\ngrounds, and what the caller was told.\n\n`error_id` is the id the caller was handed, so a user's report resolves to this record. The\nrequest it belongs to is the record's own `request_id`.",
      "x-audit-kind": "context"
    },
    "AssignmentAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "update_generic_table_assignments",
        "update_namespace_assignments",
        "update_project_assignments",
        "update_role_assignments",
        "update_server_assignments",
        "update_table_assignments",
        "update_tag_assignments",
        "update_view_assignments",
        "update_warehouse_assignments"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name"
    },
    "AssumedRoleRecord": {
      "type": "object",
      "properties": {
        "role_id": {
          "type": "string",
          "description": "The role's id in this catalog."
        },
        "provider_id": {
          "type": "string",
          "description": "The provider that supplied the role."
        },
        "source_id": {
          "type": "string",
          "description": "The role's id at the provider."
        }
      },
      "required": [
        "role_id",
        "provider_id",
        "source_id"
      ],
      "description": "The role an `assumed_role` actor acts as.",
      "x-audit-kind": "part"
    },
    "AuditOperation": {
      "type": "string",
      "description": "Values of `operation`. A later release may add a value without a format change.",
      "x-audit-values": [
        "admission_decided",
        "grant_created",
        "grant_revoked"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "operation"
    },
    "AuditOutcome": {
      "type": "string",
      "description": "Values of `outcome`. A later release may add a value without a format change.",
      "x-audit-values": [
        "forbidden",
        "success",
        "unavailable"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "outcome",
      "x-audit-descriptions": {
        "forbidden": "An admission gate denied the caller authoritatively.",
        "success": "The operation completed.",
        "unavailable": "An admission gate could not reach an upstream it needs and failed closed: an outage,\nnot a denial."
      }
    },
    "AuditRecord": {
      "type": "object",
      "description": "An audit record, whatever its shape. `record_type` names the shape that describes the rest of it.",
      "properties": {
        "event_source": {
          "const": "audit",
          "description": "Marks the line as an audit record. Always `audit`."
        },
        "audit_format": {
          "type": "string",
          "pattern": "^[0-9]+\\.[0-9]+$",
          "description": "The `MAJOR.MINOR` version of the record's shape. Compare each half as an integer."
        },
        "record_type": {
          "type": "string",
          "description": "Which shape the record has. A value this schema does not list is a newer record type."
        }
      },
      "required": [
        "event_source",
        "audit_format",
        "record_type"
      ],
      "allOf": [
        {
          "if": {
            "properties": {
              "record_type": {
                "const": "authorization"
              }
            },
            "required": [
              "record_type"
            ]
          },
          "then": {
            "$ref": "#/$defs/AuthorizationRecord"
          }
        },
        {
          "if": {
            "properties": {
              "record_type": {
                "const": "operation"
              }
            },
            "required": [
              "record_type"
            ]
          },
          "then": {
            "$ref": "#/$defs/OperationRecord"
          }
        },
        {
          "if": {
            "properties": {
              "record_type": {
                "const": "replay"
              }
            },
            "required": [
              "record_type"
            ]
          },
          "then": {
            "$ref": "#/$defs/ReplayRecord"
          }
        }
      ],
      "x-audit-kind": "part"
    },
    "AuthnAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "assume_role"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name"
    },
    "AuthorizationFailureReason": {
      "type": "string",
      "description": "Values of `failure_reason`. A later release may add a value without a format change.",
      "x-audit-values": [
        "action_forbidden",
        "cannot_see_resource",
        "internal_authorization_error",
        "internal_catalog_error",
        "invalid_request_data",
        "resource_not_found"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "failure_reason",
      "x-audit-descriptions": {
        "action_forbidden": "Action is not allowed for the user",
        "cannot_see_resource": "Resource exists but user lacks permission to see it",
        "internal_authorization_error": "Authorization backend service is unavailable",
        "internal_catalog_error": "An internal Catalog error occurred before authorization check could be completed",
        "invalid_request_data": "Invalid data provided by the client that caused authorization to fail (e.g. malformed resource identifier)",
        "resource_not_found": "Resource does not exist"
      }
    },
    "AuthorizationRecord": {
      "type": "object",
      "properties": {
        "record_type": {
          "description": "Names this record's shape. Always `authorization`.",
          "const": "authorization"
        },
        "emitters": {
          "type": "object",
          "minProperties": 1,
          "propertyNames": {
            "pattern": "^[a-z][a-z0-9]*(_[a-z0-9]+)*$"
          },
          "additionalProperties": {
            "type": "string",
            "pattern": "^[0-9]+\\.[0-9]+$"
          },
          "description": "Every product that contributed to this record, keyed by its name, with the version of\nwhat it contributes: the one that assembled it and any whose vocabulary it carries."
        },
        "request_id": {
          "$ref": "#/$defs/RequestId",
          "description": "The request this record belongs to: the `x-request-id` the caller sent, or the one\nLakekeeper generated and returned in that header."
        },
        "time": {
          "type": "string",
          "format": "date-time",
          "description": "When the event happened, in UTC: when the request was decided or answered, not when\nthe line was written."
        },
        "actions": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/ActionRecord"
          },
          "description": "The actions evaluated, always a list however many there are."
        },
        "entities": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/EntityRecord"
          },
          "description": "The entities they were evaluated against, always a list."
        },
        "actor": {
          "$ref": "#/$defs/ActorRecord",
          "description": "Who made the request, as authentication established it."
        },
        "privilege_source": {
          "$ref": "#/$defs/PrivilegeSource",
          "description": "Which authority answered: the authorizer, or a bypass."
        },
        "user_agent": {
          "type": "string",
          "description": "The `User-Agent` header, verbatim and unverified. Absent when none was sent."
        },
        "break_glass": {
          "type": "string",
          "description": "The stated break-glass reason. Absent unless the caller claimed one."
        },
        "context": {
          "description": "Handler-supplied detail about the request. Absent when the handler added none.",
          "$ref": "#/$defs/HandlerContext"
        },
        "authorizations": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/DecisionRecord"
          },
          "description": "One entry per permission evaluated."
        },
        "idempotency_key": {
          "type": "string",
          "description": "The request's `Idempotency-Key`. Absent when the caller sent none."
        },
        "decision": {
          "$ref": "#/$defs/Decision",
          "description": "Whether the request was permitted."
        },
        "failure_reason": {
          "description": "Why a denied record was denied, as the vocabulary spells it.",
          "$ref": "#/$defs/AuthorizationFailureReason"
        },
        "error": {
          "description": "The error the caller received. Present only on a denial that produced one.",
          "$ref": "#/$defs/ErrorRecord"
        }
      },
      "required": [
        "record_type",
        "emitters",
        "request_id",
        "time",
        "actions",
        "entities",
        "actor",
        "privilege_source",
        "authorizations",
        "decision"
      ],
      "description": "An authorization record: was this caller permitted to do these actions on these entities?",
      "x-audit-kind": "shape"
    },
    "CatalogGenericTableAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "control_tasks",
        "drop",
        "get_metadata",
        "get_tasks",
        "include_in_list",
        "manage_tags",
        "read_data",
        "read_grants",
        "rename",
        "set_protection",
        "undrop",
        "write_data"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "manage_tags": "Attach/detach governance tags on this generic table.",
        "read_grants": "Can list the grants held on this generic table."
      }
    },
    "CatalogNamespaceAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "accept_moved_namespace",
        "create_generic_table",
        "create_namespace",
        "create_table",
        "create_view",
        "delete",
        "get_metadata",
        "include_in_list",
        "list_everything",
        "list_generic_tables",
        "list_namespaces",
        "list_tables",
        "list_views",
        "manage_tags",
        "move",
        "read_grants",
        "read_subtree_grants",
        "revoke_subtree_grants",
        "set_protection",
        "update_properties"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "accept_moved_namespace": "Accept a namespace being moved in from elsewhere as a child of this entity.\n\nDistinct from `create_namespace`: creating adds an *empty* child, so exposing it to\nthis subtree's grantees exposes nothing. A move arrives carrying existing contents\nand their direct grants, which is why this is gated on grant authority in addition to\n`create` — without it, a namespace could be populated and granted somewhere\npermissive and then moved into a `managed_access` subtree, smuggling grants past the\ncontrol that subtree exists to enforce.",
        "manage_tags": "Attach/detach governance tags on this namespace.",
        "move": "Move this namespace to a new path, re-parenting and/or renaming it.\n\nGated on grant-level authority *in addition to* plain write access. Re-parenting a\nnamespace re-issues every privilege the destination subtree confers onto the\nnamespace's contents, with no assignment record anywhere — so the actor must\nalready be able to grant on the namespace being moved. Inside a `managed_access`\nsubtree ownership does not confer that, which is precisely the case where moving\nout would otherwise defeat the control.\n\nOnly the source half of a move's authorization; the destination is gated by\n`CreateNamespace` plus `AcceptMovedNamespace`.",
        "read_grants": "Can list the grants held on this namespace.",
        "read_subtree_grants": "Can list and read every grant in the subtree rooted here: the namespace's own and\nthose on every descendant namespace and tabular. Strictly stronger than\n`read_grants`, which covers this one resource; granted separately because it\nenumerates the subtree.\n\n`scope` states what the listing covers — the resource kinds it reaches, how far its\nrange extends, the privileges it covers, and the principal it is narrowed to — so a\npolicy can allow a narrow access review and still refuse a full enumeration.\n\nEvery enforced check carries it: Lakekeeper authorizes a real subtree listing or\nrevoke only with a scope. An absent scope is the base-capability question that\npermission introspection asks, so an authorizer may answer the two separately —\nrefusing the base question drops the action from\n`GET /{warehouse,namespace}/{id}/actions` and leaves real calls untouched.",
        "revoke_subtree_grants": "Can revoke any grant in the subtree rooted here, asked once at this namespace for\nthe whole batch. An authorizer must answer it as authority over everything\nbeneath — or refuse the subtree routes.\n\n`scope` states what the revoke covers, on the same terms as `read_subtree_grants`."
      }
    },
    "CatalogProjectAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "control_project_tasks",
        "create_role",
        "create_tag",
        "create_warehouse",
        "delete",
        "get_endpoint_statistics",
        "get_metadata",
        "get_project_tasks",
        "get_task_queue_config",
        "include_in_list",
        "list_roles",
        "list_tags",
        "list_warehouses",
        "modify_task_queue_config",
        "read_grants",
        "read_subtree_grants",
        "rename",
        "search_roles"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "create_tag": "Create a new governance tag definition in this project.",
        "list_tags": "List tag definitions in this project.",
        "read_grants": "Can list the grants held on this project.",
        "read_subtree_grants": "Can list every grant one principal holds anywhere in this project: on the project,\nits warehouses, namespaces, tables, views, generic tables and tag definitions.\nCovers more than `read_grants`, which covers the project's own grants. Not listed in\nproject actions where the authorizer keeps its own grants (OpenFGA), because the\nlisting is not available there.\n\n`scope` states what the listing covers, on the same terms as the warehouse's\n`read_subtree_grants`. Every enforced check carries it; an absent scope is the\nbase-capability question permission introspection asks."
      }
    },
    "CatalogRoleAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "delete",
        "manage_role_assignments",
        "read",
        "read_metadata",
        "read_role_assignments",
        "update",
        "update_source_system"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "manage_role_assignments": "Can add/remove members (user or role) of this role.",
        "read_role_assignments": "Can list members / parents / assignments of this role.",
        "update_source_system": "Can rebind this role's external identity (provider + source id) to a\ndifferent source system. `target` is the rebind destination, surfaced as\naction context (`requested_provider_id` / `requested_source_id`) so policy-based\nauthorizers can gate it (e.g. forbid moving a role onto a particular\nprovider). The built-in authorizer treats this the same as\n`manage_role_assignments`.\n\nA real rebind names the target provider and source id. Permission introspection\n(`GET /role/{id}/actions`) and any \"may this principal rebind at all?\" query name\n`any`. `any` is a base-capability marker, not a permissive default: a policy written\nagainst a concrete destination never matches `any`, and a `/check` caller chooses\nbetween the two."
      }
    },
    "CatalogServerAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "create_project",
        "delete_users",
        "list_users",
        "provision_users",
        "read_grants",
        "update_users"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "create_project": "Can create items inside the server (can create Warehouses).",
        "delete_users": "Can delete all users on this server.",
        "list_users": "Can List all users on this server.",
        "provision_users": "Can provision user",
        "read_grants": "Can list the grants held on this server.",
        "update_users": "Can update all users on this server."
      }
    },
    "CatalogTableAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "commit",
        "control_tasks",
        "drop",
        "get_metadata",
        "get_tasks",
        "include_in_list",
        "manage_tags",
        "read_data",
        "read_grants",
        "rename",
        "set_protection",
        "undrop",
        "write_data"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "manage_tags": "Attach/detach governance tags on this table.",
        "read_grants": "Can list the grants held on this table."
      }
    },
    "CatalogTagAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "apply",
        "delete",
        "read",
        "read_attachments",
        "read_grants",
        "remove",
        "update"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "apply": "Attach this tag to a target. Also requires `manage_tags` on the target.",
        "delete": "Delete the tag definition.",
        "read": "Read the tag definition (name, description, value kind, allowed values).",
        "read_attachments": "List the targets this tag is attached to (reverse lookup). Broader disclosure\nthan `read`, so restricted to tag owners / project security admins. Distinct\nfrom `can_read_assignments`, which reads who holds apply/ownership (grants).",
        "read_grants": "Can list the grants held on this tag definition.",
        "remove": "Detach this tag from a target. Also requires `manage_tags` on the target.",
        "update": "Update the tag definition (name/description, widen scope, add allowed values)."
      }
    },
    "CatalogUserAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "delete",
        "read",
        "read_role_assignments",
        "update"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "delete": "Can delete this user",
        "read": "Can get all details of the user given its id",
        "read_role_assignments": "Can list the role assignments held by this user.",
        "update": "Can update the user."
      }
    },
    "CatalogViewAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "commit",
        "control_tasks",
        "drop",
        "get_metadata",
        "get_tasks",
        "include_in_list",
        "manage_tags",
        "read_grants",
        "rename",
        "select",
        "set_protection",
        "undrop"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "manage_tags": "Attach/detach governance tags on this view.",
        "read_grants": "Can list the grants held on this view."
      }
    },
    "CatalogWarehouseAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "accept_moved_namespace",
        "activate",
        "control_all_tasks",
        "create_namespace",
        "deactivate",
        "delete",
        "get_all_tasks",
        "get_config",
        "get_endpoint_statistics",
        "get_metadata",
        "get_task_queue_config",
        "include_in_list",
        "list_deleted_tabulars",
        "list_everything",
        "list_namespaces",
        "manage_tags",
        "modify_soft_deletion",
        "modify_task_queue_config",
        "read_grants",
        "read_subtree_grants",
        "rename",
        "revoke_subtree_grants",
        "set_format_version_policy",
        "set_protection",
        "update_storage",
        "use"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "accept_moved_namespace": "Accept a namespace being moved in from elsewhere as a child of this entity.\n\nDistinct from `create_namespace`: creating adds an *empty* child, so exposing it to\nthis subtree's grantees exposes nothing. A move arrives carrying existing contents\nand their direct grants, which is why this is gated on grant authority in addition to\n`create` — without it, a namespace could be populated and granted somewhere\npermissive and then moved into a `managed_access` subtree, smuggling grants past the\ncontrol that subtree exists to enforce.",
        "manage_tags": "Attach/detach governance tags on this warehouse.",
        "read_grants": "Can list the grants held on this warehouse.",
        "read_subtree_grants": "Can list and read every grant in the warehouse: the warehouse's own and those on\nevery namespace and tabular inside it. Strictly stronger than `read_grants`, which\ncovers this one resource; granted separately because it enumerates the subtree.\n\n`scope` states what the listing covers — the resource kinds it reaches, how far its\nrange extends, the privileges it covers, and the principal it is narrowed to — so a\npolicy can allow a narrow access review and still refuse a full enumeration.\n\nEvery enforced check carries it: Lakekeeper authorizes a real subtree listing or\nrevoke only with a scope. An absent scope is the base-capability question that\npermission introspection asks, so an authorizer may answer the two separately —\nrefusing the base question drops the action from\n`GET /{warehouse,namespace}/{id}/actions` and leaves real calls untouched.",
        "revoke_subtree_grants": "Can revoke any grant in the warehouse, asked once at the warehouse for the whole\nbatch. An authorizer must answer it as authority over everything beneath — or\nrefuse the subtree routes.\n\n`scope` states what the revoke covers, on the same terms as `read_subtree_grants`."
      }
    },
    "Decision": {
      "type": "string",
      "description": "Values of `decision`. A new value is a major format change.",
      "enum": [
        "allowed",
        "denied"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "decision"
    },
    "DecisionRecord": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "description": "The client's id for this check in a batch, or its index. Absent for single checks."
        },
        "for_principal": {
          "description": "The principal whose permission was evaluated, when it is not the request's actor.",
          "$ref": "#/$defs/SubjectRecord"
        },
        "action": {
          "$ref": "#/$defs/ActionRecord",
          "description": "The action evaluated."
        },
        "entity": {
          "$ref": "#/$defs/EntityRecord",
          "description": "The entity the action was evaluated against."
        },
        "allowed": {
          "type": "boolean",
          "description": "The authorizer's answer. Absent when an upstream error stopped the evaluation."
        },
        "determined_by": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/DeterminingFactor"
          },
          "description": "The policies or rules that determined the decision. Empty when the authorizer\nreports none. The same shape the management API returns for a check."
        }
      },
      "required": [
        "action",
        "entity",
        "determined_by"
      ],
      "description": "One entry of `authorizations[]`: which action on which entity was evaluated, for whom,\nwith what result.",
      "x-audit-kind": "part"
    },
    "DeterminingFactor": {
      "oneOf": [
        {
          "type": "object",
          "properties": {
            "policy-id": {
              "type": "string",
              "description": "Stable, authorizer-assigned identifier of the policy, such as a Cedar policy\nid. Always present."
            },
            "name": {
              "type": "string",
              "description": "Human-facing name the author gave the policy (e.g. a `@name` or\n`@id` annotation). Neither required nor guaranteed unique; absent\nwhen the author provided none."
            },
            "effect": {
              "$ref": "#/$defs/PolicyEffect",
              "description": "Whether the policy permits or forbids."
            },
            "source": {
              "type": "string",
              "description": "Opaque origin of the policy (e.g. a policy-source identifier).\nAbsent when the authorizer cannot attribute a source."
            },
            "type": {
              "type": "string",
              "const": "policy"
            }
          },
          "required": [
            "type",
            "policy-id",
            "effect"
          ],
          "description": "A policy that determined the decision, surfaced by a policy-based\nauthorizer."
        },
        {
          "type": "object",
          "properties": {
            "source": {
              "type": "string",
              "description": "Opaque, authorizer-assigned identifier of the built-in authority\ntier that granted the action. Absent when none can be attributed."
            },
            "reason": {
              "type": "string",
              "description": "Human-facing reason the tier applied (e.g. an administrator\nlockout-recovery grant). Absent when the authorizer gives none."
            },
            "type": {
              "type": "string",
              "const": "system-authority"
            }
          },
          "required": [
            "type"
          ],
          "description": "An allow contributed by a built-in/system authority tier that takes\nprecedence over normal authored policy — e.g. a recovery mechanism that\nlets a privileged system role act despite a policy that would otherwise\nforbid it. Its presence means the verdict rested on built-in authority\nrather than on a configured policy."
        },
        {
          "type": "object",
          "properties": {
            "gate": {
              "type": "string",
              "description": "Name of the admission gate that would refuse the user."
            },
            "check": {
              "type": "string",
              "description": "The gate's check that refused the user. Absent when the gate names\nnone."
            },
            "type": {
              "type": "string",
              "const": "admission-gate"
            }
          },
          "required": [
            "type",
            "gate"
          ],
          "description": "The user would be refused at admission by this gate, so the request is\ndenied whatever the policies say."
        }
      ],
      "description": "A single factor that contributed to an authorization decision.\n\nDiscriminated by `type`: `policy` names a policy the authorizer matched,\n`system-authority` records that a built-in authority tier decided the request, and\n`admission-gate` records that an admission gate would refuse the user. The schema is\na closed `oneOf` over those three, so a further kind is a schema change that generated\nclients have to be rebuilt for.",
      "x-audit-kind": "part"
    },
    "EntityRecord": {
      "type": "object",
      "properties": {
        "entity_type": {
          "$ref": "#/$defs/EntityType",
          "description": "The kind of resource: `table`, `namespace`, `warehouse`, …"
        },
        "server_id": {
          "type": "string",
          "description": "The server."
        },
        "project_id": {
          "type": "string",
          "description": "The containing project."
        },
        "warehouse_id": {
          "type": "string",
          "description": "The containing warehouse."
        },
        "namespace": {
          "type": "string",
          "description": "The namespace's name, its levels joined by `.`."
        },
        "namespace_id": {
          "type": "string",
          "description": "The namespace's id."
        },
        "table": {
          "type": "string",
          "description": "The table's name, qualified by its namespace."
        },
        "table_id": {
          "type": "string",
          "description": "The table's id."
        },
        "table_location": {
          "type": "string",
          "description": "The table's storage location."
        },
        "view": {
          "type": "string",
          "description": "The view's name, qualified by its namespace."
        },
        "view_id": {
          "type": "string",
          "description": "The view's id."
        },
        "task_id": {
          "type": "string",
          "description": "The task's id."
        },
        "role_id": {
          "type": "string",
          "description": "The role's id in this catalog."
        },
        "role_source_id": {
          "type": "string",
          "description": "The role's id in the source it came from."
        },
        "role_provider_id": {
          "type": "string",
          "description": "The provider the role was resolved from."
        },
        "user_id": {
          "type": "string",
          "description": "The user's id."
        },
        "generic_table": {
          "type": "string",
          "description": "The generic table's name, qualified by its namespace."
        },
        "generic_table_id": {
          "type": "string",
          "description": "The generic table's id."
        },
        "tag_definition_id": {
          "type": "string",
          "description": "The tag definition's id."
        }
      },
      "required": [
        "entity_type"
      ],
      "additionalProperties": {
        "type": "string"
      },
      "description": "An `entity` object: the kind of resource and its identifying fields.",
      "x-audit-kind": "part"
    },
    "EntityType": {
      "type": "string",
      "description": "Values of `entity_type`. A later release may add a value without a format change.",
      "x-audit-values": [
        "generic-table",
        "namespace",
        "project",
        "role",
        "server",
        "table",
        "tag",
        "task",
        "user",
        "view",
        "warehouse"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "entity_type"
    },
    "ErrorRecord": {
      "type": "object",
      "properties": {
        "type": {
          "type": "string",
          "description": "The error type the caller received."
        },
        "code": {
          "type": "integer",
          "format": "uint16",
          "minimum": 0,
          "maximum": 65535,
          "description": "The HTTP status the caller received."
        },
        "message": {
          "type": "string",
          "description": "The error message the caller received."
        },
        "stack": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "The error's stack of causes, innermost first. Empty when the error has none."
        },
        "error_id": {
          "type": "string",
          "description": "The id the caller can quote to correlate with this record."
        }
      },
      "required": [
        "type",
        "code",
        "message",
        "stack",
        "error_id"
      ],
      "description": "The `error` object of a denied authorization record.",
      "x-audit-kind": "part"
    },
    "GrantContextRecord": {
      "type": "object",
      "properties": {
        "principal": {
          "$ref": "#/$defs/SubjectRecord",
          "description": "Who holds the grant."
        },
        "privilege": {
          "type": "string",
          "description": "The privilege name, verbatim from the authorizer's vocabulary."
        },
        "resource_type": {
          "$ref": "#/$defs/ResourceType",
          "description": "The kind of resource the grant is on."
        },
        "resource_id": {
          "type": "string",
          "description": "The exact resource. Absent for server grants, whose type is their whole identity."
        },
        "warehouse_id": {
          "type": "string",
          "description": "The containing warehouse, for warehouse-scoped resources."
        }
      },
      "required": [
        "principal",
        "privilege",
        "resource_type"
      ],
      "description": "The `context` of a grant record: the full `(principal, privilege, resource)` triple. Grants\nare hard-deleted, so after a revocation this record is the only trace of the triple.",
      "x-audit-kind": "context"
    },
    "HandlerContext": {
      "type": "object",
      "additionalProperties": true,
      "description": "The `context` object of an authorization record: what the handler recorded about the\nrequest beyond its action and its entity.\n\nOnly the keys relevant to that request appear, each described on its own. A product that\nplugs into Lakekeeper may contribute keys of its own.",
      "x-audit-kind": "part",
      "properties": {
        "self_provisioning": {
          "type": "boolean",
          "description": "Whether the user creation was the caller provisioning itself."
        },
        "invoked_by": {
          "$ref": "#/$defs/InvokingOperation",
          "description": "Which operation invoked this one, when a handler acts on behalf of another."
        },
        "queue_name": {
          "type": "string",
          "description": "The task queue an operation addressed."
        },
        "entity_id": {
          "type": "string",
          "description": "The id of the entity a task operation addressed."
        },
        "self_read": {
          "type": "boolean",
          "description": "Whether a grant read asked about the caller's own grants."
        }
      }
    },
    "InstanceAdminAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "set_warehouse_managed_by"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "set_warehouse_managed_by": "Set or clear a warehouse's managed-by marker."
      }
    },
    "InvokingOperation": {
      "type": "string",
      "description": "Values of `invoked_by`. A later release may add a value without a format change.",
      "x-audit-values": [
        "register_table_overwrite"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "invoked_by",
      "x-audit-descriptions": {
        "register_table_overwrite": "Registering a table with `overwrite`, which drops the table it replaces."
      }
    },
    "ManagementAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "apply_grants",
        "control_tasks",
        "get_task_details",
        "introspect_permissions",
        "list_projects",
        "list_tasks",
        "revoke_subtree_grants",
        "schedule_task",
        "search_tabulars",
        "search_users"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "apply_grants": "Apply a set of grants and revocations to one resource.",
        "revoke_subtree_grants": "Revoke the grants in a range beneath one resource."
      }
    },
    "OperationRecord": {
      "type": "object",
      "properties": {
        "record_type": {
          "description": "Names this record's shape. Always `operation`.",
          "const": "operation"
        },
        "emitters": {
          "type": "object",
          "minProperties": 1,
          "propertyNames": {
            "pattern": "^[a-z][a-z0-9]*(_[a-z0-9]+)*$"
          },
          "additionalProperties": {
            "type": "string",
            "pattern": "^[0-9]+\\.[0-9]+$"
          },
          "description": "Every product that contributed to this record, keyed by its name, with the version of\nwhat it contributes: the one that assembled it and any whose vocabulary it carries."
        },
        "request_id": {
          "description": "The request this record belongs to. Absent for an operation no request triggered.",
          "$ref": "#/$defs/RequestId"
        },
        "time": {
          "type": "string",
          "format": "date-time",
          "description": "When the operation happened, in UTC."
        },
        "operation": {
          "type": "string",
          "x-audit-open": true,
          "description": "What was done, from the emitter's own vocabulary."
        },
        "actor": {
          "$ref": "#/$defs/ActorRecord",
          "description": "Who made the request, as authentication established it."
        },
        "outcome": {
          "type": "string",
          "x-audit-open": true,
          "description": "How it ended, from the emitter's own vocabulary."
        },
        "context": {
          "description": "The operation's own detail. One shape per operation kind, each declared by its\nemitter; absent for an operation that carries none."
        }
      },
      "required": [
        "record_type",
        "emitters",
        "time",
        "operation",
        "actor",
        "outcome"
      ],
      "description": "An operation record: something the system did that touches identity or access, with no\npermission decision of its own. Any emitter can produce one.",
      "x-audit-kind": "shape"
    },
    "PermissionAction": {
      "type": "string",
      "description": "Values of `action_name`. A later release may add a value without a format change.",
      "x-audit-values": [
        "can_get_metadata",
        "can_read_assignments",
        "can_set_managed_access"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "action_name",
      "x-audit-descriptions": {
        "can_get_metadata": "Read an object's metadata. Checked when the caller checks their own access to an\nobject, and when the caller reads an object's authorization properties.",
        "can_read_assignments": "Read who holds which relation on an object. Checked when the caller checks another\nprincipal's access to an object, and when the caller reads its assignments.",
        "can_set_managed_access": "Change whether an object's grants are managed. Checked when the caller sets managed\naccess on a warehouse or a namespace."
      }
    },
    "PolicyEffect": {
      "type": "string",
      "description": "Values of `effect`. A new value is a major format change.",
      "enum": [
        "forbid",
        "permit"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "effect",
      "x-audit-descriptions": {
        "forbid": "The policy denies the action.",
        "permit": "The policy grants the action."
      }
    },
    "PrivilegeScope": {
      "type": "string",
      "description": "Values of `privilege_scope`. A new value is a major format change.",
      "enum": [
        "every",
        "only"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "privilege_scope"
    },
    "PrivilegeSource": {
      "type": "string",
      "description": "Values of `privilege_source`. A later release may add a value without a format change.",
      "x-audit-values": [
        "authorizer",
        "instance_admin",
        "internal"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "privilege_source",
      "x-audit-descriptions": {
        "authorizer": "Decision came from the configured authorizer (OpenFGA, Cedar, allow-all, ...).",
        "instance_admin": "Principal listed in `LAKEKEEPER__INSTANCE_ADMINS`. Control-plane bypass\nonly; data-plane actions still route through the configured authorizer.",
        "internal": "A call the catalog made to itself, with no client request behind it. Full bypass,\nincluding data-plane actions."
      }
    },
    "RecordType": {
      "type": "string",
      "description": "Values of `record_type`. A later release may add a value without a format change.",
      "x-audit-values": [
        "authorization",
        "operation",
        "replay"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "record_type",
      "x-audit-descriptions": {
        "authorization": "Was this caller permitted to do these actions on these entities?",
        "operation": "Something the system did that touches identity or access.",
        "replay": "A retry answered from an idempotency record, so no authorization ran."
      }
    },
    "ReplayRecord": {
      "type": "object",
      "properties": {
        "record_type": {
          "description": "Names this record's shape. Always `replay`.",
          "const": "replay"
        },
        "emitters": {
          "type": "object",
          "minProperties": 1,
          "propertyNames": {
            "pattern": "^[a-z][a-z0-9]*(_[a-z0-9]+)*$"
          },
          "additionalProperties": {
            "type": "string",
            "pattern": "^[0-9]+\\.[0-9]+$"
          },
          "description": "Every product that contributed to this record, keyed by its name, with the version of\nwhat it contributes: the one that assembled it and any whose vocabulary it carries."
        },
        "request_id": {
          "$ref": "#/$defs/RequestId",
          "description": "The request this record belongs to: the `x-request-id` the caller sent, or the one\nLakekeeper generated and returned in that header."
        },
        "time": {
          "type": "string",
          "format": "date-time",
          "description": "When the event happened, in UTC: when the request was decided or answered, not when\nthe line was written."
        },
        "actions": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/ActionRecord"
          },
          "description": "The actions the replayed request named, always a list."
        },
        "entities": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/EntityRecord"
          },
          "description": "The entities it named, always a list. As the caller wrote them: a replay resolves\nnothing."
        },
        "actor": {
          "$ref": "#/$defs/ActorRecord",
          "description": "Who made the request, as authentication established it."
        },
        "privilege_source": {
          "$ref": "#/$defs/PrivilegeSource",
          "description": "Which authority would have answered, had one been asked."
        },
        "user_agent": {
          "type": "string",
          "description": "The `User-Agent` header, verbatim and unverified. Absent when none was sent."
        },
        "idempotency_key": {
          "type": "string",
          "description": "The key whose stored response was served. Always present: it is what makes this a\nreplay."
        }
      },
      "required": [
        "record_type",
        "emitters",
        "request_id",
        "time",
        "actions",
        "entities",
        "actor",
        "privilege_source",
        "idempotency_key"
      ],
      "description": "A replay record: a retry answered from an idempotency record, so no authorization ran.",
      "x-audit-kind": "shape"
    },
    "RequestId": {
      "type": "string",
      "description": "The id of one request, as everything that names the request carries it: the response's\n`x-request-id`, the log lines written while serving it, its audit records and its events.\n\nThe client's `x-request-id` when it sent one, whatever its form; otherwise a UUIDv7\ngenerated for the request.",
      "x-audit-kind": "part"
    },
    "ResourceType": {
      "type": "string",
      "description": "Values of `resource_type`. A later release may add a value without a format change.",
      "x-audit-values": [
        "generic-table",
        "namespace",
        "project",
        "server",
        "table",
        "tag-definition",
        "view",
        "warehouse"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "resource_type",
      "x-audit-descriptions": {
        "tag-definition": "A tag definition, spelled as the path segment tag definitions are addressed by."
      }
    },
    "RoleSubjectRecord": {
      "type": "object",
      "properties": {
        "role": {
          "type": "string",
          "description": "The role's id."
        }
      },
      "required": [
        "role"
      ],
      "description": "A role named as a target.",
      "x-audit-kind": "part"
    },
    "RootLevelGrants": {
      "type": "string",
      "description": "Values of `root_level`. A new value is a major format change.",
      "enum": [
        "excluded",
        "included"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "root_level",
      "x-audit-descriptions": {
        "excluded": "Only grants held below the addressed resource are in range.",
        "included": "The request's range extends to the addressed resource itself. The kinds it\nactually reaches are in `resource_types`; a kind filter can still exclude the\nroot's own kind."
      }
    },
    "SubjectRecord": {
      "anyOf": [
        {
          "$ref": "#/$defs/UserSubjectRecord",
          "description": "A user."
        },
        {
          "$ref": "#/$defs/RoleSubjectRecord",
          "description": "A role."
        }
      ],
      "description": "A principal named as a target: `for_principal` on a decision entry, `principal` on a grant\nrecord. `{\"user\": …}` or `{\"role\": …}`.",
      "x-audit-kind": "part"
    },
    "TableUpdateKind": {
      "type": "string",
      "description": "Values of `update_kinds`. A later release may add a value without a format change.",
      "x-audit-values": [
        "add-encryption-key",
        "add-schema",
        "add-snapshot",
        "add-sort-order",
        "add-spec",
        "assign-uuid",
        "remove-encryption-key",
        "remove-partition-specs",
        "remove-partition-statistics",
        "remove-properties",
        "remove-schemas",
        "remove-snapshot-ref",
        "remove-snapshots",
        "remove-statistics",
        "set-current-schema",
        "set-default-sort-order",
        "set-default-spec",
        "set-location",
        "set-partition-statistics",
        "set-properties",
        "set-snapshot-ref",
        "set-statistics",
        "upgrade-format-version"
      ],
      "x-audit-kind": "enum",
      "x-audit-field": "update_kinds"
    },
    "UserSubjectRecord": {
      "type": "object",
      "properties": {
        "user": {
          "type": "string",
          "description": "The user's principal id."
        }
      },
      "required": [
        "user"
      ],
      "description": "A user named as a target.",
      "x-audit-kind": "part"
    }
  }
}
