package iam import ( "context" "atlas9.dev/c/core" ) // SystemGrant grants a platform-operator role to a principal across the whole // system — the "platform plane", distinct from tenant-scoped grants. It has no // tenant or path: system access is global by nature. Managed out-of-band / // gated, not through the tenant grant API. type SystemGrant struct { Principal core.ID Role string } var ( CapSystemGrantsAdd = NewCap("SystemGrants_Add") CapSystemGrantsRemove = NewCap("SystemGrants_Remove") CapSystemGrantsList = NewCap("SystemGrants_List") ) type SystemGrantStore interface { Add(ctx context.Context, g SystemGrant) error Remove(ctx context.Context, g SystemGrant) error List(ctx context.Context, page core.PageReq) (core.Page[SystemGrant], error) }