CLI reference / Access

CLI reference

Access

wiele access: list, explain, grant and revoke access to workspace files and folders.

Content roles are read, write and admin. A grant on a folder covers everything under it; a grant on a file covers that file. The highest grant that applies wins. Listing and changing grants needs admin on the path.

wiele access list

List direct grants on a workspace path, as a source admin.

wiele access list [flags] [<path>]
Argument Description
<path> Optional. Workspace path. Default: /.
Flag Description
--workspace string Workspace ID, slug or name. Not needed inside a checkout or when the path is written as WORKSPACE:/path.
--org string Organization ID or slug. Default: the checkout's organization when the workspace comes from the checkout, otherwise the one picked with wiele org use.

wiele access explain

Explain a user's effective role on a path and every grant behind it.

wiele access explain [flags] [<path>]
Argument Description
<path> Optional. Workspace path. Default: /.
Flag Description
--user string User ID or member email; defaults to yourself.
--branch string Explain the branch role, its basis and whether you can publish to main.
--workspace string Workspace ID, slug or name. Not needed inside a checkout or when the path is written as WORKSPACE:/path.
--org string Organization ID or slug. Default: the checkout's organization when the workspace comes from the checkout, otherwise the one picked with wiele org use.

wiele access show

Show the direct grants on one file or folder and the policy epoch, as a source admin.

wiele access show [flags] <resource>
Argument Description
<resource> Resource ID of the file or folder, from wiele stat.
Flag Description
--workspace string Required. Workspace ID, such as ws_..., from wiele workspace list. This command does not look up names or slugs.
--org string Organization ID or slug. Default: the checkout's organization when the workspace comes from the checkout, otherwise the one picked with wiele org use.

wiele access invite

Invite someone to workspace paths with one content role.

wiele access invite [flags] <email>
Argument Description
<email> Email address to invite.
Flag Description
--path string Required. Workspace path to share, such as /clients/acme. Repeat the flag for up to 20 paths.
--role read|write|admin Content role on every path. Default: read.
--workspace string Workspace ID, slug or name. Not needed inside a checkout or when the path is written as WORKSPACE:/path.
--org string Organization ID or slug. Default: the checkout's organization when the workspace comes from the checkout, otherwise the one picked with wiele org use.
--idempotency-key string UUIDv7 that makes the request safe to retry. Each run generates one; pass the same key to replay a request after a timeout.

wiele access grant

Give an organization member a content role on one file or folder.

wiele access grant [flags] <resource>
Argument Description
<resource> Resource ID of the file or folder, from wiele stat.
Flag Description
--workspace string Required. Workspace ID, such as ws_..., from wiele workspace list. This command does not look up names or slugs.
--org string Organization ID or slug. Default: the checkout's organization when the workspace comes from the checkout, otherwise the one picked with wiele org use.
--user string Required. User ID of the member, from wiele org members list.
--role read|write|admin Content role to grant. Default: read.
--epoch integer Required. The organization's current policy epoch, from wiele org show or wiele access show. Read it again after any access change.
--idempotency-key string UUIDv7 that makes the request safe to retry. Each run generates one; pass the same key to replay a request after a timeout.

wiele access revoke

Remove a member's direct grant on one file or folder.

wiele access revoke [flags] <resource>
Argument Description
<resource> Resource ID of the file or folder, from wiele stat.
Flag Description
--workspace string Required. Workspace ID, such as ws_..., from wiele workspace list. This command does not look up names or slugs.
--org string Organization ID or slug. Default: the checkout's organization when the workspace comes from the checkout, otherwise the one picked with wiele org use.
--user string Required. User ID of the member, from wiele org members list.
--role read|write|admin Not used by revoke, which removes the member's direct grant whatever its role. Default: read.
--epoch integer Required. The organization's current policy epoch, from wiele org show or wiele access show. Read it again after any access change.
--idempotency-key string UUIDv7 that makes the request safe to retry. Each run generates one; pass the same key to replay a request after a timeout.