System resource actions
TaruviBase creates a system policy for each supported resource, such as a DataTable, a function, a storage bucket, or a saved analytics query. A rule in that policy can grant only the actions its resource type accepts. Use this table to choose action names when you narrow the initial rules.
Choose a system resource#
| System resource | Policy kind | Actions |
|---|---|---|
| Database | datatable:TABLE | read, create, update, delete |
| Functions | function:SLUG | execute |
| Storage | storage:BUCKET | read, create, update, delete |
| Analytics | query:SLUG | execute |
System policies are edited in the Console, not recreated as custom policies.
Related#
- Automatic system policies: which resources receive a system policy and the initial access each one grants.
- Manage policies in the Console: review and replace a full policy definition.
- Test access decisions: run one expected-allow and one expected-deny check after each change.