revoke
End an active access grant to an agent, effective on the next read. Keeps all records and audit evidence intact, and reports whether a live grant was actually retired.
Instructions
End a grant -- same arguments as grant. Effective on the NEXT read.
It DELETES NOTHING: the owner keeps every record, any other agent's independent grant is untouched (a
different granter or grantee is a different grant), and the withdrawn grant stays in grant_log() as
evidence that the access existed and ended. was_granted in the result says whether a live grant was
actually retired or you revoked something that had never been given.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| by | No | ||
| ids | No | ||
| key | No | ||
| tag | No | ||
| note | No | ||
| agent | Yes | ||
| scope | No |