Platform access and consent
An extension does not receive a generic client capable of browsing a merchant's objects. Every access to a platform object goes through a bounded, verifiable path.
Two access paths
| Voie | What it allows | What it does not allow |
|---|---|---|
| Process | Receive an explicitly bound object or perform an active access covered by a declared permission. | Freely explore the merchant outside the granted context. |
| Mapping exact | Resolve the exact platform object already correlated to an external identity for this configuration. | Listing, arbitrary search, relationship traversal, or implicit mutation. |
Any new access path must be considered forbidden by default until an explicit public contract makes it legitimate.
Visible binding: functional consent
When a process author explicitly supplies a complete object to a node parameter, the extension already receives that value. It does not perform an active platform read.
The binding explicitly passes the complete object to the node; no additional active read is needed.
This visible binding materializes functional consent to use that object as an input. It does not authorize the node to take its ID and silently load additional objects.
Opaque access: explicit permission
If a node selects, searches, reads, or modifies an object on its own when that object was not already supplied as a complete parameter, the access is opaque to the process author and must be declared.
platform_access: [
{ object: 'credit_exposure', access: 'read' }
]Declare only the objects and modes that are actually required. A declaration write does not replace business authority: the operation must still be legitimate under the object's contract.
Mapping resolution
A mapping lets the extension find exactly the object already associated with an external identity in the current configuration. This capability survives later removal of the consent that allowed the correlation to be established, but remains limited to the exact target of the mapping.
- no search by arbitrary platform ID;
- no listing;
- no transitive navigation through relationships;
- no mutation right derived from the mapping alone;
- no resolution to a type different from the expected one.
Revocation and scope
Opaque permissions belong to the process and context that granted them. An extension must not remember a grant as a durable right reusable elsewhere.
Revocation must take effect on the next relevant active access. It does not rewrite the history of past executions and does not automatically remove legitimate mappings that were already established.