> ## Documentation Index
> Fetch the complete documentation index at: https://docs.assetinfinity.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Grant and revoke a set of a role's permissions together.

> Every change is applied in one transaction: if any one is refused, none of them are made and the
role keeps exactly the permissions it had. Each change is checked as a single grant or revoke
would be, so granting needs admin.role.create and revoking needs admin.role.delete.

Granting a permission the role already holds, or revoking one it does not, is not an error; it is
counted as unchanged. Naming the same permission in both lists is refused. Where an approval is
required for these changes, the ones held for it are counted rather than applied.

Returns the role's id and how many permissions were granted, revoked, unchanged and held for
approval. The System Administrator role holds every permission and cannot be narrowed, and the
Platform Support role cannot be changed at all.



## OpenAPI

````yaml /api-reference/openapi.json post /rpc/set_role_permissions
openapi: 3.0.0
info:
  description: ''
  title: >-
    The only schema PostgREST exposes. Reads are security_invoker views; writes
    are SECURITY DEFINER functions. Rebuilt wholesale on every deploy — it holds
    no data.
  version: 12.2.3
servers:
  - url: https://app.assetinfinity.ai/api
security: []
tags:
  - name: Signing in
  - name: Profile
  - name: Assets
  - name: Asset lifecycle
  - name: Work lifecycle
  - name: Maintenance
  - name: Inventory
  - name: Inventory detail
  - name: Procurement
  - name: Contracts
  - name: Workforce
  - name: Capacity
  - name: Dispatch
  - name: Tools
  - name: Inspections
  - name: Verification
  - name: Reliability
  - name: Parts demand
  - name: Sensors and meters
  - name: Map
  - name: Floor plans
  - name: Labels
  - name: Lost and found
  - name: Root cause analysis
  - name: Reports
  - name: Audit center
  - name: Activity
  - name: Notifications
  - name: Channels
  - name: Search
  - name: Copilot
  - name: Import
  - name: Files
  - name: Sync
  - name: Support
  - name: Admin
  - name: Access
  - name: Lookups
  - name: Read models
  - name: Branding
  - name: Custom fields
  - name: Form studio
  - name: Workflows
  - name: Workflow studio
  - name: Rules
  - name: Statuses and transitions
  - name: Currencies and locales
  - name: Work configuration
  - name: Asset configuration
  - name: Inventory configuration
  - name: Tool configuration
  - name: Workforce configuration
  - name: Vendor and contract configuration
  - name: Document configuration
  - name: Inspection configuration
  - name: Sites, locations and the organisation
  - name: Platform
  - name: Amendments
  - name: Asset clone
  - name: Asset components
  - name: Asset register
  - name: Asset transfer
  - name: Audit feed
  - name: Billing
  - name: Bookings
  - name: Budgets
  - name: Bulk jobs
  - name: Calibration history
  - name: Capex plans
  - name: Conversations
  - name: Costing
  - name: Currency
  - name: Dashboards
  - name: Directory sync
  - name: Document control
  - name: Document folders
  - name: Document tree
  - name: Documents
  - name: Energy
  - name: Extracts
  - name: Features
  - name: Feeds
  - name: Ffe plans
  - name: File exchange
  - name: Filing exceptions
  - name: Finance
  - name: Inbound mail
  - name: Keys
  - name: Knowledge
  - name: Licence
  - name: List views
  - name: Locations
  - name: Mapping
  - name: Mcp
  - name: Mcp oauth
  - name: Mfa
  - name: Numbering
  - name: Permits
  - name: Readers
  - name: Reference
  - name: Reference columns
  - name: Reference entry
  - name: Release
  - name: Scim
  - name: Security streams
  - name: Self verification
  - name: Setup
  - name: Shutdown
  - name: Sso
  - name: Telegram
  - name: Tenant switch
  - name: The caller's own work
  - name: The checklist library
  - name: Tools on a job, and who has them out
  - name: Tray
  - name: Vendor spend forecast
  - name: Vendors and contracts
  - name: Visitors
  - name: Work order execution
  - name: Work sequencing
  - name: Workforce detail
externalDocs:
  description: PostgREST Documentation
  url: https://postgrest.org/en/v12/references/api.html
paths:
  /rpc/set_role_permissions:
    post:
      tags:
        - Admin
      summary: Grant and revoke a set of a role's permissions together.
      description: >-
        Every change is applied in one transaction: if any one is refused, none
        of them are made and the

        role keeps exactly the permissions it had. Each change is checked as a
        single grant or revoke

        would be, so granting needs admin.role.create and revoking needs
        admin.role.delete.


        Granting a permission the role already holds, or revoking one it does
        not, is not an error; it is

        counted as unchanged. Naming the same permission in both lists is
        refused. Where an approval is

        required for these changes, the ones held for it are counted rather than
        applied.


        Returns the role's id and how many permissions were granted, revoked,
        unchanged and held for

        approval. The System Administrator role holds every permission and
        cannot be narrowed, and the

        Platform Support role cannot be changed at all.
      parameters:
        - $ref: '#/components/parameters/preferParams'
      requestBody:
        content:
          application/json:
            schema:
              description: >-
                Grant and revoke a set of a role's permissions together.


                Every change is applied in one transaction: if any one is
                refused, none of them are made and the

                role keeps exactly the permissions it had. Each change is
                checked as a single grant or revoke

                would be, so granting needs admin.role.create and revoking needs
                admin.role.delete.


                Granting a permission the role already holds, or revoking one it
                does not, is not an error; it is

                counted as unchanged. Naming the same permission in both lists
                is refused. Where an approval is

                required for these changes, the ones held for it are counted
                rather than applied.


                Returns the role's id and how many permissions were granted,
                revoked, unchanged and held for

                approval. The System Administrator role holds every permission
                and cannot be narrowed, and the

                Platform Support role cannot be changed at all.
              properties:
                p_grant:
                  format: uuid[]
                  items:
                    type: string
                  type: array
                p_revoke:
                  format: uuid[]
                  items:
                    type: string
                  type: array
                p_role_id:
                  format: uuid
                  type: string
              required:
                - p_role_id
              type: object
          application/vnd.pgrst.object+json:
            schema:
              description: >-
                Grant and revoke a set of a role's permissions together.


                Every change is applied in one transaction: if any one is
                refused, none of them are made and the

                role keeps exactly the permissions it had. Each change is
                checked as a single grant or revoke

                would be, so granting needs admin.role.create and revoking needs
                admin.role.delete.


                Granting a permission the role already holds, or revoking one it
                does not, is not an error; it is

                counted as unchanged. Naming the same permission in both lists
                is refused. Where an approval is

                required for these changes, the ones held for it are counted
                rather than applied.


                Returns the role's id and how many permissions were granted,
                revoked, unchanged and held for

                approval. The System Administrator role holds every permission
                and cannot be narrowed, and the

                Platform Support role cannot be changed at all.
              properties:
                p_grant:
                  format: uuid[]
                  items:
                    type: string
                  type: array
                p_revoke:
                  format: uuid[]
                  items:
                    type: string
                  type: array
                p_role_id:
                  format: uuid
                  type: string
              required:
                - p_role_id
              type: object
          application/vnd.pgrst.object+json;nulls=stripped:
            schema:
              description: >-
                Grant and revoke a set of a role's permissions together.


                Every change is applied in one transaction: if any one is
                refused, none of them are made and the

                role keeps exactly the permissions it had. Each change is
                checked as a single grant or revoke

                would be, so granting needs admin.role.create and revoking needs
                admin.role.delete.


                Granting a permission the role already holds, or revoking one it
                does not, is not an error; it is

                counted as unchanged. Naming the same permission in both lists
                is refused. Where an approval is

                required for these changes, the ones held for it are counted
                rather than applied.


                Returns the role's id and how many permissions were granted,
                revoked, unchanged and held for

                approval. The System Administrator role holds every permission
                and cannot be narrowed, and the

                Platform Support role cannot be changed at all.
              properties:
                p_grant:
                  format: uuid[]
                  items:
                    type: string
                  type: array
                p_revoke:
                  format: uuid[]
                  items:
                    type: string
                  type: array
                p_role_id:
                  format: uuid
                  type: string
              required:
                - p_role_id
              type: object
          text/csv:
            schema:
              description: >-
                Grant and revoke a set of a role's permissions together.


                Every change is applied in one transaction: if any one is
                refused, none of them are made and the

                role keeps exactly the permissions it had. Each change is
                checked as a single grant or revoke

                would be, so granting needs admin.role.create and revoking needs
                admin.role.delete.


                Granting a permission the role already holds, or revoking one it
                does not, is not an error; it is

                counted as unchanged. Naming the same permission in both lists
                is refused. Where an approval is

                required for these changes, the ones held for it are counted
                rather than applied.


                Returns the role's id and how many permissions were granted,
                revoked, unchanged and held for

                approval. The System Administrator role holds every permission
                and cannot be narrowed, and the

                Platform Support role cannot be changed at all.
              properties:
                p_grant:
                  format: uuid[]
                  items:
                    type: string
                  type: array
                p_revoke:
                  format: uuid[]
                  items:
                    type: string
                  type: array
                p_role_id:
                  format: uuid
                  type: string
              required:
                - p_role_id
              type: object
        required: true
      responses:
        '200':
          description: OK
components:
  parameters:
    preferParams:
      description: Preference
      in: header
      name: Prefer
      required: false
      schema:
        enum:
          - params=single-object
        type: string

````