# RoleDescriptor

object type

One allow/disallow descriptor: service:action + polarity, per-segment \* wildcards; segments drawn verbatim from the operation registry.

## Fields

| Field | Type | Notes |
| --- | --- | --- |
| `service` | [String](/types/#scalars) `String!` | The logical service name (today: api), or \*. |
| `action` | [String](/types/#scalars) `String!` | The service external operation name (a schema Query/Mutation field), or \*. |
| `polarity` | [RoleDescriptorPolarity](/types/RoleDescriptorPolarity/) `RoleDescriptorPolarity!` | No further notes. |
