> ## Documentation Index
> Fetch the complete documentation index at: https://docs.assetinfinity.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Who can do what, and how widely. reaches_every_site is true when a user has no site grants, personal or through a role (role-based data access) — the sites list is the union of both, deduplicated.

> Absent rows mean unrestricted (identity.can_access_site), which is the opposite of what an empty
list looks like. The invitation columns are null for anybody who was never invited — the first
administrator of a tenant, and every service account. linked_organizations is how many other tenants
the same person holds a live account in — zero for almost everybody.

worker_id is null for an account nobody put on the workforce, and also for one based at a site the
reader is not scoped to: workforce.workers carries a site policy and this view is security-invoker.



## OpenAPI

````yaml /api-reference/openapi.json get /user_access
openapi: 3.0.0
info:
  description: ''
  title: >-
    The only schema PostgREST exposes. Reads are security_invoker views; writes
    are SECURITY DEFINER functions. Rebuilt wholesale on every deploy — it holds
    no data.
  version: 12.2.3
servers:
  - url: https://app.assetinfinity.ai/api
security: []
tags:
  - name: Signing in
  - name: Profile
  - name: Assets
  - name: Asset lifecycle
  - name: Work lifecycle
  - name: Maintenance
  - name: Inventory
  - name: Inventory detail
  - name: Procurement
  - name: Contracts
  - name: Workforce
  - name: Capacity
  - name: Dispatch
  - name: Tools
  - name: Inspections
  - name: Verification
  - name: Reliability
  - name: Parts demand
  - name: Sensors and meters
  - name: Map
  - name: Floor plans
  - name: Labels
  - name: Lost and found
  - name: Root cause analysis
  - name: Reports
  - name: Audit center
  - name: Activity
  - name: Notifications
  - name: Channels
  - name: Search
  - name: Copilot
  - name: Import
  - name: Files
  - name: Sync
  - name: Support
  - name: Admin
  - name: Access
  - name: Lookups
  - name: Read models
  - name: Branding
  - name: Custom fields
  - name: Form studio
  - name: Workflows
  - name: Workflow studio
  - name: Rules
  - name: Statuses and transitions
  - name: Currencies and locales
  - name: Work configuration
  - name: Asset configuration
  - name: Inventory configuration
  - name: Tool configuration
  - name: Workforce configuration
  - name: Vendor and contract configuration
  - name: Document configuration
  - name: Inspection configuration
  - name: Sites, locations and the organisation
  - name: Platform
  - name: Amendments
  - name: Asset clone
  - name: Asset components
  - name: Asset register
  - name: Asset transfer
  - name: Audit feed
  - name: Billing
  - name: Bookings
  - name: Budgets
  - name: Bulk jobs
  - name: Calibration history
  - name: Capex plans
  - name: Conversations
  - name: Costing
  - name: Currency
  - name: Dashboards
  - name: Directory sync
  - name: Document control
  - name: Document folders
  - name: Document tree
  - name: Documents
  - name: Energy
  - name: Extracts
  - name: Features
  - name: Feeds
  - name: File exchange
  - name: Filing exceptions
  - name: Finance
  - name: Inbound mail
  - name: Keys
  - name: Knowledge
  - name: Licence
  - name: List views
  - name: Locations
  - name: Mapping
  - name: Mcp
  - name: Mcp oauth
  - name: Mfa
  - name: Numbering
  - name: Permits
  - name: Readers
  - name: Reference
  - name: Reference columns
  - name: Reference entry
  - name: Release
  - name: Scim
  - name: Security streams
  - name: Self verification
  - name: Setup
  - name: Shutdown
  - name: Sso
  - name: Telegram
  - name: Tenant switch
  - name: The caller's own work
  - name: The checklist library
  - name: Tools on a job, and who has them out
  - name: Tray
  - name: Vendor spend forecast
  - name: Vendors and contracts
  - name: Visitors
  - name: Work order execution
  - name: Work sequencing
  - name: Workforce detail
externalDocs:
  description: PostgREST Documentation
  url: https://postgrest.org/en/v12/references/api.html
paths:
  /user_access:
    get:
      tags:
        - Access
      summary: >-
        Who can do what, and how widely. reaches_every_site is true when a user
        has no site grants, personal or through a role (role-based data access)
        — the sites list is the union of both, deduplicated.
      description: >-
        Absent rows mean unrestricted (identity.can_access_site), which is the
        opposite of what an empty

        list looks like. The invitation columns are null for anybody who was
        never invited — the first

        administrator of a tenant, and every service account.
        linked_organizations is how many other tenants

        the same person holds a live account in — zero for almost everybody.


        worker_id is null for an account nobody put on the workforce, and also
        for one based at a site the

        reader is not scoped to: workforce.workers carries a site policy and
        this view is security-invoker.
      parameters:
        - $ref: '#/components/parameters/rowFilter.user_access.id'
        - $ref: '#/components/parameters/rowFilter.user_access.email'
        - $ref: '#/components/parameters/rowFilter.user_access.username'
        - $ref: '#/components/parameters/rowFilter.user_access.sign_in_handle'
        - $ref: '#/components/parameters/rowFilter.user_access.name'
        - $ref: '#/components/parameters/rowFilter.user_access.phone'
        - $ref: '#/components/parameters/rowFilter.user_access.status'
        - $ref: '#/components/parameters/rowFilter.user_access.is_service_account'
        - $ref: '#/components/parameters/rowFilter.user_access.last_login_at'
        - $ref: '#/components/parameters/rowFilter.user_access.roles'
        - $ref: '#/components/parameters/rowFilter.user_access.effective_permissions'
        - $ref: '#/components/parameters/rowFilter.user_access.has_no_roles'
        - $ref: '#/components/parameters/rowFilter.user_access.reaches_every_site'
        - $ref: '#/components/parameters/rowFilter.user_access.sites'
        - $ref: '#/components/parameters/rowFilter.user_access.linked_organizations'
        - $ref: '#/components/parameters/rowFilter.user_access.invitation_sent_at'
        - $ref: '#/components/parameters/rowFilter.user_access.invitation_expires_at'
        - $ref: '#/components/parameters/rowFilter.user_access.invitation_sends'
        - $ref: '#/components/parameters/rowFilter.user_access.invitation_is_live'
        - $ref: '#/components/parameters/rowFilter.user_access.worker_id'
        - $ref: '#/components/parameters/rowFilter.user_access.worker_number'
        - $ref: '#/components/parameters/rowFilter.user_access.worker_name'
        - $ref: '#/components/parameters/rowFilter.user_access.worker_type'
        - $ref: '#/components/parameters/rowFilter.user_access.worker_is_active'
        - $ref: '#/components/parameters/rowFilter.user_access.worker_teams'
        - $ref: '#/components/parameters/rowFilter.user_access.row_version'
        - $ref: '#/components/parameters/select'
        - $ref: '#/components/parameters/order'
        - $ref: '#/components/parameters/range'
        - $ref: '#/components/parameters/rangeUnit'
        - $ref: '#/components/parameters/offset'
        - $ref: '#/components/parameters/limit'
        - $ref: '#/components/parameters/preferCount'
      responses:
        '200':
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/user_access'
                type: array
            application/vnd.pgrst.object+json:
              schema:
                items:
                  $ref: '#/components/schemas/user_access'
                type: array
            application/vnd.pgrst.object+json;nulls=stripped:
              schema:
                items:
                  $ref: '#/components/schemas/user_access'
                type: array
            text/csv:
              schema:
                items:
                  $ref: '#/components/schemas/user_access'
                type: array
          description: OK
        '206':
          description: Partial Content
components:
  parameters:
    rowFilter.user_access.id:
      in: query
      name: id
      required: false
      schema:
        type: string
    rowFilter.user_access.email:
      in: query
      name: email
      required: false
      schema:
        type: string
    rowFilter.user_access.username:
      in: query
      name: username
      required: false
      schema:
        type: string
    rowFilter.user_access.sign_in_handle:
      in: query
      name: sign_in_handle
      required: false
      schema:
        type: string
    rowFilter.user_access.name:
      in: query
      name: name
      required: false
      schema:
        type: string
    rowFilter.user_access.phone:
      in: query
      name: phone
      required: false
      schema:
        type: string
    rowFilter.user_access.status:
      in: query
      name: status
      required: false
      schema:
        type: string
    rowFilter.user_access.is_service_account:
      in: query
      name: is_service_account
      required: false
      schema:
        type: string
    rowFilter.user_access.last_login_at:
      in: query
      name: last_login_at
      required: false
      schema:
        type: string
    rowFilter.user_access.roles:
      in: query
      name: roles
      required: false
      schema:
        type: string
    rowFilter.user_access.effective_permissions:
      in: query
      name: effective_permissions
      required: false
      schema:
        type: string
    rowFilter.user_access.has_no_roles:
      in: query
      name: has_no_roles
      required: false
      schema:
        type: string
    rowFilter.user_access.reaches_every_site:
      in: query
      name: reaches_every_site
      required: false
      schema:
        type: string
    rowFilter.user_access.sites:
      in: query
      name: sites
      required: false
      schema:
        type: string
    rowFilter.user_access.linked_organizations:
      in: query
      name: linked_organizations
      required: false
      schema:
        type: string
    rowFilter.user_access.invitation_sent_at:
      in: query
      name: invitation_sent_at
      required: false
      schema:
        type: string
    rowFilter.user_access.invitation_expires_at:
      in: query
      name: invitation_expires_at
      required: false
      schema:
        type: string
    rowFilter.user_access.invitation_sends:
      in: query
      name: invitation_sends
      required: false
      schema:
        type: string
    rowFilter.user_access.invitation_is_live:
      in: query
      name: invitation_is_live
      required: false
      schema:
        type: string
    rowFilter.user_access.worker_id:
      in: query
      name: worker_id
      required: false
      schema:
        type: string
    rowFilter.user_access.worker_number:
      in: query
      name: worker_number
      required: false
      schema:
        type: string
    rowFilter.user_access.worker_name:
      in: query
      name: worker_name
      required: false
      schema:
        type: string
    rowFilter.user_access.worker_type:
      in: query
      name: worker_type
      required: false
      schema:
        type: string
    rowFilter.user_access.worker_is_active:
      in: query
      name: worker_is_active
      required: false
      schema:
        type: string
    rowFilter.user_access.worker_teams:
      in: query
      name: worker_teams
      required: false
      schema:
        type: string
    rowFilter.user_access.row_version:
      in: query
      name: row_version
      required: false
      schema:
        type: string
    select:
      description: Filtering Columns
      in: query
      name: select
      required: false
      schema:
        type: string
    order:
      description: Ordering
      in: query
      name: order
      required: false
      schema:
        type: string
    range:
      description: Limiting and Pagination
      in: header
      name: Range
      required: false
      schema:
        type: string
    rangeUnit:
      description: Limiting and Pagination
      in: header
      name: Range-Unit
      required: false
      schema:
        default: items
        type: string
    offset:
      description: Limiting and Pagination
      in: query
      name: offset
      required: false
      schema:
        type: string
    limit:
      description: Limiting and Pagination
      in: query
      name: limit
      required: false
      schema:
        type: string
    preferCount:
      description: Preference
      in: header
      name: Prefer
      required: false
      schema:
        enum:
          - count=none
        type: string
  schemas:
    user_access:
      description: >-
        Who can do what, and how widely. reaches_every_site is true when a user
        has no site grants, personal or through a role (role-based data access)
        — the sites list is the union of both, deduplicated.


        Absent rows mean unrestricted (identity.can_access_site), which is the
        opposite of what an empty

        list looks like. The invitation columns are null for anybody who was
        never invited — the first

        administrator of a tenant, and every service account.
        linked_organizations is how many other tenants

        the same person holds a live account in — zero for almost everybody.


        worker_id is null for an account nobody put on the workforce, and also
        for one based at a site the

        reader is not scoped to: workforce.workers carries a site policy and
        this view is security-invoker.
      properties:
        effective_permissions:
          format: bigint
          type: integer
        email:
          format: public.citext
          type: string
        has_no_roles:
          format: boolean
          type: boolean
        id:
          description: |-
            Note:
            This is a Primary Key.<pk/>
          format: uuid
          type: string
        invitation_expires_at:
          format: timestamp with time zone
          type: string
        invitation_is_live:
          format: boolean
          type: boolean
        invitation_sends:
          format: integer
          type: integer
        invitation_sent_at:
          format: timestamp with time zone
          type: string
        is_service_account:
          format: boolean
          type: boolean
        last_login_at:
          format: timestamp with time zone
          type: string
        linked_organizations:
          format: integer
          type: integer
        name:
          format: character varying
          maxLength: 200
          type: string
        phone:
          format: character varying
          maxLength: 40
          type: string
        reaches_every_site:
          format: boolean
          type: boolean
        roles:
          format: jsonb
        row_version:
          format: bigint
          type: integer
        sign_in_handle:
          format: text
          type: string
        sites:
          format: jsonb
        status:
          format: character varying
          maxLength: 30
          type: string
        username:
          format: public.citext
          type: string
        worker_id:
          description: |-
            Note:
            This is a Primary Key.<pk/>
          format: uuid
          type: string
        worker_is_active:
          format: boolean
          type: boolean
        worker_name:
          format: character varying
          maxLength: 200
          type: string
        worker_number:
          format: character varying
          maxLength: 60
          type: string
        worker_teams:
          format: jsonb
        worker_type:
          format: character varying
          maxLength: 150
          type: string
      type: object

````