RBAC · Schema
RBAC Role Assignment
An association between a principal (user, group, or service account) and a role within a Role-Based Access Control system.
Access ControlAuthorizationCloud NativeComplianceIdentity ManagementKubernetesRBACSecurity
Properties
| Name | Type | Description |
|---|---|---|
| id | string | Unique identifier for the assignment. |
| principalId | string | Identifier of the user, group, or service account being assigned the role. |
| principalType | string | Type of principal. |
| roleId | string | Identifier of the role being assigned. |
| scope | string | Scope of the assignment (e.g., global, organization, project, resource). |
| grantedBy | string | Identifier of the principal that granted this assignment. |
| grantedAt | string | |
| expiresAt | string | Optional expiration timestamp for time-limited assignments. |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://raw.githubusercontent.com/api-evangelist/rbac/refs/heads/main/json-schema/rbac-assignment.json",
"title": "RBAC Role Assignment",
"description": "An association between a principal (user, group, or service account) and a role within a Role-Based Access Control system.",
"type": "object",
"required": ["principalId", "roleId"],
"properties": {
"id": {
"type": "string",
"description": "Unique identifier for the assignment."
},
"principalId": {
"type": "string",
"description": "Identifier of the user, group, or service account being assigned the role."
},
"principalType": {
"type": "string",
"enum": ["user", "group", "service_account"],
"description": "Type of principal."
},
"roleId": {
"type": "string",
"description": "Identifier of the role being assigned."
},
"scope": {
"type": "string",
"description": "Scope of the assignment (e.g., global, organization, project, resource)."
},
"grantedBy": {
"type": "string",
"description": "Identifier of the principal that granted this assignment."
},
"grantedAt": {
"type": "string",
"format": "date-time"
},
"expiresAt": {
"type": "string",
"format": "date-time",
"description": "Optional expiration timestamp for time-limited assignments."
}
}
}