Who can do what, and how widely. reaches_every_site is true when a user has no site grants, personal or through a role (role-based data access) — the sites list is the union of both, deduplicated.
Absent rows mean unrestricted (identity.can_access_site), which is the opposite of what an empty list looks like. The invitation columns are null for anybody who was never invited — the first administrator of a tenant, and every service account. linked_organizations is how many other tenants the same person holds a live account in — zero for almost everybody.
worker_id is null for an account nobody put on the workforce, and also for one based at a site the reader is not scoped to: workforce.workers carries a site policy and this view is security-invoker.
Headers
Limiting and Pagination
Limiting and Pagination
Preference
count=none Query Parameters
Filtering Columns
Ordering
Limiting and Pagination
Limiting and Pagination
Response
OK
Note: This is a Primary Key.
2004030Note: This is a Primary Key.
20060150
