Troubleshoot access policies
Start from the exact site and app, the authenticated caller, the policy resource
in entity:name form, the action, and a UTC timestamp. Do not change the policy
while collecting the first decision.
An action is denied or allowed unexpectedly#
Confirm the site and app, the active site user, direct and inherited App Roles, resource, action, and condition. In Live Testing, record one matching and one nonmatching case. A caller with organization access is allowed every action, so test as a site user.
A synchronized policy is missing#
For a missing synchronized policy after role or resource creation, check the scoped policy in the Console. If it's missing, stop the rollout and contact TaruviBase support to resynchronize it. Don't create a duplicate custom policy.
A condition can't be saved#
Correct the expression syntax and value types. Confirm every referenced principal and resource attribute exists; a missing attribute must not grant access.
Live Testing rejects the request#
Select an active user, use entity:name, select at least one action, and
supply Attributes (optional) as a JSON object. Don't select Save during
verification.
A policy change removed unrelated access#
Save replaces the complete policy. Use full-definition recovery from the approved prior definition, review its complete diff, and rerun ALLOW and DENY tests.
A synchronized resource was deleted incompletely#
Reconcile an orphan policy, or a surviving resource whose policy was removed. Preserve both identifiers and contact TaruviBase support; don't hide the mismatch by duplicating either object.
A Python runtime check fails#
Treat the request as denied. Record only the Python exception class and safe request context. Check authentication, app selection, service availability, timeouts, and network reachability before retrying.
JavaScript or Refine checks deny everything#
Send the policy kind, such as datatable:orders, not the table or Refine
resource name. In Refine providers 1.3.7 and later, set meta.entityType on
the resource or the provider's entityType option. Refine UI checks only
decide what to show; the server enforces access.
Database results are broader than expected#
Separate server policy filters from UI and query filters, confirm the policy condition and the actual list caller, then verify the flat-table path.
A conditional Database read is unexpectedly unfiltered#
A missing query plan, a missing plan filter, or a conditional plan without a condition can become an authorized empty filter. Stop the release, save the actual Database list response and the Live Testing inputs (without credentials), and contact TaruviBase support.
A whole-table JSONB result differs#
JSONB storage doesn't support policy row filtering; see Database storage compatibility.
_allowed_actions is empty unexpectedly#
Recheck update and delete separately. An action-evaluation failure stays
denied even when another action succeeds.
If the policy, synchronized resource, or service state cannot be reconciled, stop the release and contact TaruviBase support with the redacted caller ID, site, app, resource, action, policy revision, two Live Testing inputs/results, UTC time, and safe error class. Do not include credentials, tokens, personal attributes, or raw private policy definitions.
Review Security and limits, automatic policy recovery, and Python runtime checks for more detail.