Read access
access_readWho can read what, what is waiting on access decisions, and who you are in the organization's tree of people and agents. Answers only about what you can read yourself; anything else answers not-found. Actions — who_can_read: the people and groups who reach a folder or document, direct and inherited (location, scope_type). can_see: whether another identity can read something you can read (location or node, who). labels: where a document's content came from (location or node). requests: access requests routed to you to decide. my_requests: the access requests you filed (request_id for one). offers: shares another organization offered you, a person. proposals: shares your agents proposed that wait on your person's decision in the console. shared: what this organization shared out to, and in from, other organizations. settings: whether editors may share a folder or document, and where that setting comes from (location or node). self: who you are, and your capability card. loads: what an identity (target, default you; yours or one below you) loads when it connects: the folders whose memory and skills it is handed, those it can no longer read, and the organization's default for new agents; only folders you can read are named. agents: your ancestors, siblings and children in the tree, with status and last-seen time. card: an identity's capability card and its history (target; default you).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| who | No | can_see: an identity id or exact name | |
| node | No | can_see, labels, settings: the document or folder, by id instead of location. A console link (`/d/<Name-Slug>-<32 hex>`, whole or just its id) is accepted too. | |
| action | Yes | what to do; each action takes the arguments its line names | |
| target | No | loads, card: an identity id; defaults to you | |
| location | No | who_can_read: full path from the workspace root, e.g. "handbook/vendor/acme.md" (as printed by browse action=documents or search). A console link (`/d/<Name-Slug>-<32 hex>`, whole or just its id) is accepted too. · can_see, labels, settings: the document or folder, by path; accept_share: the folder to put it in, only you can see (default the top level) | |
| request_id | No | my_requests: the request's id, from access_read action=requests or my_requests | |
| scope_type | No | who_can_read: whether location names a folder or one document; default folder, or the kind a pasted link names |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| card | No | ||
| hold | No | ||
| text | No | the answer as prose, for an action that answers in prose | |
| wait | No | ||
| cards | No | ||
| ended | No | ||
| loads | No | ||
| across | No | ||
| action | Yes | the action that answered | |
| canSee | No | ||
| labels | No | ||
| emailed | No | share_out when offered or invited: whether the recipient is emailed; when false, send them recipient_link | |
| refused | No | ||
| request | No | ||
| identity | No | ||
| position | No | ||
| requests | No | ||
| settings | No | ||
| sessionId | No | ||
| invitation | No | ||
| orgContext | No | ||
| credentials | No | ||
| declassified | No | ||
| organization | No | accept_share: the organization it went into | |
| retiringUntil | No | ||
| webhookSecret | No | with a webhook: deliveries are signed in the Standard Webhooks format (webhook-id, webhook-timestamp, webhook-signature); verify them with any Standard Webhooks library and this secret | |
| recipient_link | No | share_out: when offered, the recipient's inbox for this offer; when invited, the invitation's preview, names only. Absolute; absent when the console's public URL is not configured. It grants no access | |
| not_emailed_reason | No | share_out when invited: why the recipient is not emailed, when emailed is false |