revoke
Remove a subject's circle assignment and record the intent, with the subject falling back to default access. Revoking an unassigned subject still logs the action.
Instructions
Remove a subject's circle assignment. Consent-carrying: calling this IS the approval.
The subject does not become unknown again — their request line stays in the log, and they fall back to whatever an unmapped authenticated caller gets. Revoking somebody who was never assigned is a no-op that still records the intent.
Tier: owner.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| subject | Yes |