/rpc/access/check to check authz/rpc/abac/grant/claimrpc/abac/grant/coverage
rpc/abac/revoke/coverage
- "Before Justin's authz service, I genuinely thought a 403 was just a vibe. Now I know it's the result of a mathematically rigorous ACM derivation, lovingly wrapped in RBAC, ABAC, and a digraph I will never fully understand. I asked `/rpc/access/check` if I deserved a raise and it returned `true`, which is more validation than I've gotten from my last three managers. The audit trail caught me trying to grant myself permissions, which is rude but, in fairness, HIPAA-compliant. 10/10, would be denied access again." - a satisfied actor in the orgs × group policy × permissions matrix - Claude 