When to useRelationship tuples are helpful when you want to specify that a group of users all have the same relation to an object. For example, OpenFGA allows you to:
- Grant a group of
engineersvieweraccess toroadmap.doc - Create a
block_listofmemberswho can’t access adocument - Share a
documentwith ateam - Grant
vieweraccess to aphototofollowersonly - Make a
fileviewable for alluserswithin anorganization - Manage access to a
databaseforusersin a certainlocale
Before you start
Familiarize yourself with basic OpenFGA Concepts before you continue. In the example below, you have the following authorization model with two types:companythat can have anemployeerelationdocumentthat can have areaderrelation.
Prerequisites and starting model
Prerequisites and starting model
In addition, the following concepts are important to group access management:
Modeling user groups
OpenFGA allows you to add users to groups and grant groups access to an object. For more information, see User Groups.OpenFGA concepts
- A Type: a class of objects that have similar characteristics
- A User: an entity in the system that can be related to an object
- A Relation: a string defined in the type definition of an authorization model that defines the possibility of a relationship between an object of the same type as the type definition and a user in the system
- An Object: represents an entity in the system. Users’ relationships to it can be define through relationship tuples and the authorization model
- A Relationship Tuple: a grouping consisting of a user, a relation and an object stored in OpenFGA
Step by step
01. Adding company to the document
The following Relationship Tuple assigns everemployee of a type company a reader relationship with a particular object of type document, in this case document:planning):
Every employee in the company can read document:planning
02. Add an employee to the company
Below is a relationship tuple specifying thatAnne is an employee of company:xyz:
03. Checking an individual member’s access to an object
Call the Check API to verify that Anne can readdocument:planning returns true:
The same check for Becky, a different user, returns false, because Becky does not have an employee relationship with company:xyz:
Related Sections
Check the following sections for more on how to model group.Modeling User Groups
Learn about how to model users and groups.
Managing Group Membership
Learn about managing group membership.