# Role

object type

A role — the group-scoped, merchant-authored authorization construct: 0..N allow/disallow descriptors over the service:action naming universe. Evaluation is flat: default-DENY, union the allow descriptors across the session-user acted-org ACTIVE roles, any matching disallow ALWAYS wins; per-segment \* wildcards; no specificity ranking.

## Fields

| Field | Type | Notes |
| --- | --- | --- |
| `id` | [ID](/types/#scalars) `ID!` | The record’s id — a UUID the platform assigned when the record was created; every reference to this record uses it. |
| `sysId` | [String](/types/#scalars) `String!` | The group-scoped human-facing system id (RL-…). |
| `type` | [String](/types/#scalars) `String!` | The kind of record — always `Role` here. |
| `caption` | [String](/types/#scalars) `String!` | The record’s display name — what people see it called. |
| `status` | [String](/types/#scalars) `String!` | The FSM state: active \| inactive \| doomed. |
| `parentId` | [ID](/types/#scalars) `ID!` | The parent org group; for a Role parentId === rootId. |
| `rootId` | [ID](/types/#scalars) `ID!` | The org-group family root. |
| `createdAt` | [String](/types/#scalars) `String!` | When the record was created, as a UTC timestamp. |
| `updatedAt` | [String](/types/#scalars) `String!` | When the record last changed, as a UTC timestamp. |
| `revisionNum` | [Int](/types/#scalars) `Int!` | How many times this record has been edited; the first save is 0. |
| `revision` | [ID](/types/#scalars) `ID!` | The OCC revision token — supply it on every mutation of this record; rotates on every write. |
| `refCaptions` | [RefCaption](/types/RefCaption/) `[RefCaption!]!` | The server-composed captions of this record's declared references (the referenced-caption rule) — one row per referenced id; see RefCaption. |
| `descriptors` | [RoleDescriptor](/types/RoleDescriptor/) `[RoleDescriptor!]!` | The allow/disallow descriptors: service:action + polarity, per-segment \* wildcards, disallow-wins; non-\* segments are drawn VERBATIM from the operation registry (STRICT at create/edit). May be empty (grants nothing — default-deny). |
| `templateKey` | [RoleTemplateKey](/types/RoleTemplateKey/) | PROVENANCE: the canned template this Role was copied from (copyCannedRole); PORT-stamped, never caller-suppliable; absent on from-scratch roles. A copy NEVER auto-revs when the template does (fork semantics). |
| `templateVersion` | [Int](/types/#scalars) | PROVENANCE: the template version the copy compiled from; absent on from-scratch roles. |
| `authorityTier` | [RoleTemplateKey](/types/RoleTemplateKey/) | The authority tier this Role confers: stamped from the template at copy; editable via updateRole (role administration is — hard-disallowed to every non-admin template, so tier self-elevation is structurally out); absent ⇒ contributes NO tier (deny-by-default at the authority gate). A role carrying an effective allow api:\* counts as owner tier regardless (the bootstrap-role rule). |

## Used by

- [copyCannedRole](/reference/identity-and-access/copyCannedRole/)
- [createRole](/reference/role/createRole/)
- [deactivateRole](/reference/role/deactivateRole/)
- [doomRole](/reference/role/doomRole/)
- [reactivateRole](/reference/role/reactivateRole/)
- [role](/reference/role/role/)
- [updateRole](/reference/role/updateRole/)
