# EffectivePermission

object type

One operation's evaluation under the flat algorithm: permitted ⟺ at least one allow matched AND no disallow matched (default-DENY, disallow-wins; per-segment \* wildcards; ONLY active roles contribute).

## Fields

| Field | Type | Notes |
| --- | --- | --- |
| `service` | [String](/types/#scalars) `String!` | The logical service name (today: api). |
| `action` | [String](/types/#scalars) `String!` | The service external operation name (a schema Query/Mutation field). |
| `permitted` | [Boolean](/types/#scalars) `Boolean!` | No further notes. |
| `allows` | [DescriptorContribution](/types/DescriptorContribution/) `[DescriptorContribution!]!` | The allow descriptors that matched, attributed to their carrying roles. |
| `disallows` | [DescriptorContribution](/types/DescriptorContribution/) `[DescriptorContribution!]!` | The disallow descriptors that matched (ANY entry here forces permitted: false), attributed to their carrying roles. |
