# NewRoleInput

input type

Create-input for a Role. The tenant (org group — the Role parent) is derived SERVER-SIDE from the principal — NEVER supplied here. descriptors is required but MAY be empty; at most 100 per role; exact duplicates refused; non-\* segments must name the live operation registry (STRICT).

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `caption` | [String](/types/#scalars) | no | Optional: when omitted the per-type default applies — the constant 'Role'; when supplied it must be non-blank. |
| `descriptors` | [RoleDescriptorInput](/types/RoleDescriptorInput/) `[RoleDescriptorInput!]!` | yes | The allow/disallow descriptors; may be empty (grants nothing). |
| `authorityTier` | [RoleTemplateKey](/types/RoleTemplateKey/) | no | Optional authority tier; absent ⇒ the role confers no tier (deny-by-default at the authority gate). |

## Used by

- [createRole](/reference/role/createRole/)
