set_object_permissions
Replace the full grant list on a dashboard, report, budget, or cost alert. One tool for all four kinds — pass resourceKind, the object id, and the complete intended grants array. Omitted principals lose access. Roles are READER, EDITOR, or ADMIN. ORGANIZATION may be Reader or Editor, never Admin. CLERK_ADMIN may use any role and applies only to Clerk organization admins; omit it for No access. Every replacement must retain at least one USER, TEAM, or CLERK_ADMIN Admin grant, so empty grants[] is invalid. Call get_object_permissions first, then send the full list including grants you want to keep. New creates start as creator-only Admin and do not include CLERK_ADMIN. Do not use PRIVATE/PUBLIC or teamId on create/update tools. Resolve people with list_users (userId) and teams with list_teams (teamId) — both list the full organization, not only membership.
EXAMPLES:
• "Share the AWS dashboard read-only with the whole org" (keep yourself as Admin) → { resourceKind: "dashboard", resourceId: "clx9aws", grants: [{ principalType: "USER", userId: "", role: "ADMIN" }, { principalType: "ORGANIZATION", role: "READER" }] }
• "Give the infra team Editor on this budget" (keep yourself as Admin) → { resourceKind: "budget", resourceId: "clx9bud", grants: [{ principalType: "USER", userId: "", role: "ADMIN" }, { principalType: "TEAM", teamId: "team_xyz", role: "EDITOR" }] }
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| slug | No | Organization slug. Omit to auto-detect from your account (fails if you belong to multiple orgs). | |
| grants | Yes | Full replacement of direct grants. Omitted principals lose access. Every object must retain a USER, TEAM, or CLERK_ADMIN Admin grant. Each principal may appear once. | |
| resourceId | Yes | Object id from search, get, or create. | |
| resourceKind | Yes | dashboard, report, budget, or costAlert. Budget alerts use the parent budget. |