Deny reasons
A deny decision carries only a DenyReason and the fixed text shown to the person. It never carries a policy, a rule or a classification. masked on OpenedRecord carries the same reason for each withheld field.
Denied
interface Denied { outcome: 'deny'; eventId: EventId; reason: DenyReason; text: string;}struct Denied { let eventId: EventId let reason: DenyReason let text: String}data class Denied( val eventId: EventId, val reason: DenyReason, val text: String,)| Field | Type | Description |
|---|---|---|
eventId | EventId | The access event of this decision. |
reason | DenyReason | Why the request was denied. |
text | string | The fixed text of the reason, the words the person sees. |
masked
masked lists each field on OpenedRecord that the policies withheld. The SDK reports each one in the field’s place, beside the open’s allow, not as a separate error.
masked: { field: string; reason: DenyReason; text: string }[];let masked: [(field: String, reason: DenyReason, text: String)]val masked: List<MaskedField>
data class MaskedField(val field: String, val reason: DenyReason, val text: String)Every reason
| Reason | Swift | Kotlin | When | What the app can offer |
|---|---|---|---|---|
not-entitled | .notEntitled | DenyReason.NOT_ENTITLED | The person’s role does not include this action. | Show the text. Name who can give the person access. |
not-a-member | .notAMember | DenyReason.NOT_A_MEMBER | The person does not belong to the key domain. | Show the text. Say that a domain owner can share the key domain with them. |
outside-scope | .outsideScope | DenyReason.OUTSIDE_SCOPE | The record or file falls outside the person’s data scope. | Show the text. Name who can give access to the case. |
outside-hours | .outsideHours | DenyReason.OUTSIDE_HOURS | The request falls outside the hours the tenant allows for this role. | Offer to try again inside the allowed hours, or to ask for a break-glass exception. |
device | .device | DenyReason.DEVICE | The tenant limits this action to approved devices. This device is not on the list. | Retry from an approved device. |
location | .location | DenyReason.LOCATION | The tenant limits this action to approved locations. This location is not on the list. | Retry from an approved location. |
deleted | .deleted | DenyReason.DELETED | The object is in the recycle bin. | Restore it, if the person may, or ask a domain owner to. |
held | .held | DenyReason.HELD | A legal hold covers the target. | Show the hold’s reason and reference. Tell the person to wait until two Owners lift it. |
retention | .retention | DenyReason.RETENTION | The dataset’s retention floor has not passed yet. | Show the person when the floor is met. |
policy | .policy | DenyReason.POLICY | A rule the tenant added on its own refuses the request. | Show the text. Only the tenant’s own policies can change that rule. |