generated from coulomb/repo-seed
Implement canonical schema foundation
This commit is contained in:
45
examples/caring/policy_fixture.yaml
Normal file
45
examples/caring/policy_fixture.yaml
Normal file
@@ -0,0 +1,45 @@
|
||||
id: fixture:markitect-internal-read-allow
|
||||
request:
|
||||
id: check:tenant-alpha-internal-note
|
||||
subject:
|
||||
id: user:alice
|
||||
type: Human
|
||||
tenant: tenant:alpha
|
||||
action: read
|
||||
resource:
|
||||
id: document:internal-note
|
||||
type: document
|
||||
system: markitect-tool
|
||||
tenant: tenant:alpha
|
||||
caring_context:
|
||||
id: descriptor:tenant-alpha-document-reader
|
||||
profile: caring-0.4.0-rc2
|
||||
subject_type: Human
|
||||
organization_relation: Customer
|
||||
canonical_role: Doer
|
||||
scope:
|
||||
level: Resource
|
||||
id: document:internal-note
|
||||
tenant: tenant:alpha
|
||||
resource: document:internal-note
|
||||
planes:
|
||||
- Data
|
||||
capabilities:
|
||||
- View
|
||||
exposure_modes:
|
||||
- Masked
|
||||
- Plaintext
|
||||
conditions:
|
||||
- PurposeBound
|
||||
- Logged
|
||||
restrictions:
|
||||
- ExportBlocked
|
||||
expect:
|
||||
effect: allow
|
||||
reason: reader_relation
|
||||
conformance_findings:
|
||||
- code: CARING-EXPORT-SEPARATION
|
||||
severity: info
|
||||
message: View is allowed, but Exportable exposure remains separately blocked.
|
||||
metadata:
|
||||
source: examples/caring
|
||||
Reference in New Issue
Block a user