Permit.io Condition Sets API
Condition sets are sets of objects that are dynamically defined based on conditions on the objects' attributes. Conditions sets allows you the flexibility of ABAC with the simplicity of RBAC. There are currently two types of condition sets at the moment: 1) user set = the set of users that match all the specified conditions. 2) resource set = the set of resources that match all the specified conditions. Examples: - `us_based_employees` = {U1, ..., Un} = {all **users** who are *located in the US* and are *assigned the employee role*} - `private_repos` = {R1, ..., Rn} = {all **resources** *of type repository* that *are private*} We can then picture a **matrix** of assignment between *user sets* and *resource sets*. Example: If we check the checkbox where `us_based_employees` and `private_repos->clone` action intersect, we are setting a rule: *all US based employees can clone private repos*.