# AccessGrants Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/accessgrants/

Schema for the `AccessGrants` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier, verbatim -- a full ARN, resource id, or self-link. Never truncated or normalised. Use it to find the object in the provider's console.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is located. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider gives none, the collector's queried region is used instead and flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified -- for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them -- no case folding, key/value normalisation, or merging across providers. An empty object means no tags; unreadable tags appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider-supplied timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`created_at`** _(string)_
  When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Additional detail on the reason, when there is any.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`grant_id`** _(string)_
  Stable reference for this grant. Synthesized on AWS, which has no single grant identifier.
- **`principal`** _(object)_
  Who holds the grant. `user` resolves against human_identities and `workload_identity` against workload_identities. Null when `principal_type` is `group` or `external`, which have no resource in this family; the provider's id for those is kept in `remote_data.principal_arn`.
  - **`id`** _(string)_
    The target's `id`.
- **`principal_type`** _(string)_
  What kind of principal holds it.
  Allowed: `user`, `group`, `workload_identity`, `external`, `unknown`
- **`permission`** _(object)_
  What was granted. Absent for a grant with no independently addressable policy — an AWS inline policy, which lives inside its principal.
  - **`id`** _(string)_
    The target's `id`.
  - **`name`** _(string)_
    What the provider calls it.
- **`scope`** _(string)_
  The provider reference for the exact thing the grant applies to.
- **`scope_level`** _(string)_
  How far the grant reaches, from organisation level down to a single resource.
  Allowed: `organisation`, `grouping`, `account`, `resource`, `unknown`
- **`scope_id`** _(string)_
  The provider reference for the scope node.
- **`is_privileged`** _(boolean)_
  Whether this grant confers administrative privilege. Derived by parsing the permission document.
- **`grants_all_actions`** _(boolean)_
  Whether the grant permits every action on every resource, derived from the permission document including the NotAction case.
- **`assignment_type`** _(string)_
  Whether the privilege is permanent, eligible (activated on request), or time-limited with an expiry.
  Allowed: `permanent`, `eligible`, `time_limited`, `unknown`
- **`expires_at`** _(string)_
  When the grant expires. AWS IAM attachments and Identity Center assignments are permanent until detached, so this is null with not_supported_by_provider there. Session duration bounds a credential, not this grant, and is not mapped here.
- **`last_reviewed_at`** _(string)_
  When this grant was last formally reviewed. AWS has no access-review or attestation concept, so this is always null there; see last_used_at for a related but different signal.
- **`last_used_at`** _(string)_
  When the granted access was last exercised. Not a substitute for last_reviewed_at.

## Methods

- [GET /unified/cloud-infrastructure/access_grants](/docs/api-reference/unified-cloud-infrastructure-api/accessgrants/list) — List Access grants
