Record-Level Security (RLS) Permission Evaluation for Complex Role Hierarchies
SurrealDB utilizes PERMISSIONS clauses on tables and records to enforce fine-grained access control. These expressions typically evaluate the current session's user attributes against record data to determine if a SELECT , CREATE , UPDATE , or DELETE action is permitted. When implementing DEFINE ROLE for scalable management, there is a need to handle overlap