OptionaldescriptionRole description and scope
OptionalentitiesEntity field-level security rules
Unique role identifier (e.g. "reader", "curator", "admin", "ai-agent")
OptionalinheritsInherited role IDs whose permissions are automatically merged
Human-readable role name
OptionalroutesRoute-level access rules with semantic actions
OptionalsubjectAllowed subject types for this role (e.g. ['agent', 'service'] or ['human'])
OptionaltarpitRole-specific rate limiting and tarpitting policy
Role definition encapsulating route rules, entity field security, inheritance and M2M tarpitting.