propose_decomposition
Propose a permission set decomposition by clustering profiles into shared bases and deviations, verified to preserve all user permissions, providing raw material for naming and justification.
Instructions
Propose a thin-base-profile + permission-set decomposition. The STRUCTURE is computed deterministically (cluster the profiles, derive each cluster's shared base and each profile's deviation) and is run through verify_decomposition before it is returned — if it doesn't preserve every user's effective permissions, you get the failure, not the proposal. Names and rationale are deliberately NOT provided: the tool returns placeholder keys plus each base's member profile names and shared grants as raw material for YOU to name in the customer's vocabulary and justify.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| threshold | No | ||
| snapshot_id | Yes | ||
| target_base_count | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||