_dbSchema is the schema-introspection root field the shipped editor renders from. Since
the authorization-policy engine shipped, it answers per caller: the model is projected
through the same evaluator the data path enforces before anything is described, so the
answer never names something the caller may not read.
A table the caller may not read is absent from the result — the same answer a
non-existent table gets, so the filter is never an existence oracle.
A table the caller may read but with no readable column is absent too: it has nothing
selectable, and labelColumn is non-null on the wire.
A column the caller may not read is absent from its table’s columns. A foreign-key or
many-to-many edge is published only when both end tables and every participating column
are visible.
metadata (table and column) is the raw metadata bag — served to admin callers
only. Non-admin callers receive an empty list, because the bag contains the
policy-* rules themselves. This is a breaking change for non-admin consumers that
read metadata.
Subset of read, create, update, delete the caller may perform, resolved via the policy evaluator. An action the policy’s allow-list omits is absent for everyone, admins included.
isEditable
Boolean!
Compatibility field: means exactly “the table has a key”. It is not an authorization answer — read allowedActions instead.
false when the caller may not read this column’s values. A masked column (read-requires with deny-mode: null) is readable: false yet stays selectable — the selection succeeds with the value nulled. A column on the table’s policy-read-deny list is absent from the list entirely; a read-requires column with deny-mode: refuse stays listed with readable: false (S4c makes deny win over read-requires on overlap).
writable
Boolean!
false when the caller may not write the column (write-requires grant unmet, or policy-write-deny applies). Column-level only; the update/delete actions themselves are reported by allowedActions.
The caller’s own grant set: the union of roles and permissions, sorted. What a client reads to decide what its user may do.
_policyGrants
[String!]!
Every grant name referenced anywhere in the model’s policy metadata — action brackets, deny roles, row-scope roles/exemptions, column read-requires/write-requires — sorted and de-duplicated. The catalogue an app’s profile editor lists. It names grants, never which caller holds them.