Two kinds of refusal are logged at the capability gate: a signed-in person with no platform role probing a platform endpoint, and a staff member reaching for a capability their role doesn't include. Both rows carry the actor, the endpoint, the account in context and the reason.
Also called: denied access log · 403 log · attempted access · someone tried to open something
- 1The gate records a denial with reason 'no platform access' for a caller with no role at all.
- 2It records a denial with reason 'missing capability' plus the role for a staff member who lacks it.
- 3Denials are never throttled.
- 4The refusal returned to the caller names the missing capability, so a legitimate gap is diagnosable rather than mysterious.
The comment ranks these rows above the others: they are 'the most important rows in the table: someone reaching for something their role doesn't cover. A run of these is the earliest signal there is.' The other case is logged for its own reason: 'A signed-in person with no platform role probing a platform endpoint is worth a row on its own.' Not throttling them is deliberate — writes, denials and account entries 'are the record, and two of the same in a row is itself information.'
- A log of successes alone can't show someone probing for access.
- A generic refusal makes a legitimate permission gap indistinguishable from an attack.
- Throttling would hide a repeated attempt, which is itself the signal.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →