OptionalActingServer-derived acting context for this request. Consumed when a matching allow rule carries a RowFilterID whose filter references {{Acting*}} tokens: every required token must be supplied here with a type-valid value or the request is DENIED (fail closed, reason names the token).
TRUST BOUNDARY: values must originate server-side (a verified session token, a server-side lookup, a trusted upstream assertion) — never from a client-supplied header, argument, or GraphQL variable.
The API key ID (from validated key)
The application ID making the request
OptionalContextOptional additional context
The specific resource being accessed (e.g., entity name, agent name)
The scope path being requested (e.g., 'view:run', 'agent:execute')
The user ID associated with the API key
Request for authorization evaluation