# EffectivePermissions

object type

The verification mechanism: (user, org) → the FULL effective-permission map + which role contributed each descriptor, computed by the SAME evaluator the future gate uses (preview ≡ enforcement — no second mechanism, no drift). Evaluates DESCRIPTORS ONLY: it does NOT compose the account-capability / dark-org / user-lifecycle gates.

## Fields

| Field | Type | Notes |
| --- | --- | --- |
| `roles` | [EffectivePermissionsRole](/types/EffectivePermissionsRole/) `[EffectivePermissionsRole!]!` | The user roles AT the org as loaded live (deduplicated) — non-active roles visibly contribute nothing. |
| `operations` | [EffectivePermission](/types/EffectivePermission/) `[EffectivePermission!]!` | One entry registry operation (sorted — the WHOLE descriptor universe): can the user do X, and WHY, for every X. |

## Used by

- [effectivePermissions](/reference/reading-your-records/effectivePermissions/)
- [myEffectivePermissions](/reference/your-own-session/myEffectivePermissions/)
- [rolePermissions](/reference/reading-your-records/rolePermissions/)
