Hey guys, is it possible to do explicit denies? ...
# spicedb
m
Hey guys, is it possible to do explicit denies? We have Workspace Members, Member Groups and there are Projects and Assets inside that workspace. Roles can be applied for the whole Workspace, Member Groups, and Individual Members. Now, the idea is that we want the most granular permission to take effect, regardless of the applied role. Let's say a member has permissions on a project based on the workspace setting that is set to "View", the member group which is set to "Edit" and the member is added individually with the "Comment" role. Can we deny the user's "Edit" role which is set on the Member Group? Thanks!