Entity Access Control
Some entities in Trivore ID support predefined Access Control Lists (ACLs). Instead of listing individual users and groups with read/write access directly on the entity itself, those principals are grouped into a reusable Access Control object, which can then be assigned to one or more entities. This enables greater scalability, flexibility, and manageability than a per-entity access list.
Entities that support Access Control today include commerce objects — Products, Catalogs,
Pricing Plans, Discount Campaigns, Contracts, Wallets, and Wallet Types — as well as Custom
Field definitions and External Permission Groups. Since more entities can gain Access Control
support over time, check your instance's /apidoc for the current, authoritative list (look
for an accessControlIds field on a resource).
Relational model for the Access Control object
An entity references one or more Access Control objects by ID; each Access Control object separately lists which Users, Groups, and Management API Clients have read access and which have write access.