who_can_read
Who currently reaches a folder or document — people and groups inside this organization, direct and inherited, AND people outside it who hold a share. Call it after sharing to confirm the grant landed, or before sharing to see who is already there. Names people, never their content. Answers only for a scope you reach yourself; one you do not answers not-found, identical to a scope that does not exist.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| token | No | Bearer token identifying the principal. Usually omitted — supplied by the transport (HTTP Authorization header or the server's AGENTLEFS_TOKEN env). Only pass this to override. | |
| location | Yes | full path from the workspace root, e.g. "handbook/vendor/acme.md" (as printed by list_org_docs or search_org_knowledge) | |
| scope_type | No |