NewRoleInput
input type
Create-input for a Role. The tenant (org group — the Role parent) is derived SERVER-SIDE from the principal — NEVER supplied here. descriptors is required but MAY be empty; at most 100 per role; exact duplicates refused; non-* segments must name the live operation registry (STRICT).
Fields
| Field | Type | Required | Notes |
|---|---|---|---|
caption | String | no | Optional: when omitted the per-type default applies — the constant 'Role'; when supplied it must be non-blank. |
descriptors | RoleDescriptorInput [RoleDescriptorInput!]! | yes | The allow/disallow descriptors; may be empty (grants nothing). |
authorityTier | RoleTemplateKey | no | Optional authority tier; absent ⇒ the role confers no tier (deny-by-default at the authority gate). |