True when the user has this authorization or an ancestor grant.
The authorization Name that actually matched (leaf or ancestor). Null when not allowed.
The name as requested.
True when no MJ: Authorizations row matches this name. Fail-closed: Allowed is then false.
True when Allowed because of an ancestor grant, not a direct role on this row.
One row of
Authorization.Checkoutput.