In SpiceDB [0] schema this can be represented like so:
definition group {
relation member: user | group#member
}
Here `member` allows a relationship to itself, which allows writing a relationship saying that every member of one group is a member of the containing group.I threw together an example in our playground [1], if you'd like to try it out!
[0]: https://github.com/authzed/spicedb [1]: https://play.authzed.com/s/9D5h9I7mE9mK/schema
CanAccessAmericanSecrets = AllSREs - EmployeesInEnemyState
(or whatever)In addition, there is `tupleset_to_userset` [0], which can be thought of as an arrow (which is also how its defined in SpiceDB [1]).
[0]: https://zanzibar.tech/2D0HKhvxH0:0.IoJK1g_7i:4L~ses~0~1 [1]: https://docs.authzed.com/reference/schema-lang#--arrow
I was in that misled camp for quite some time. One day it clicked, but only after realizing that the namespace config pseudo-code from section 2.3. IS what defines relationships: https://gruchalski.com/posts/2022-10-22-zanzibar-with-prolog.... Not the fancy object#relation@subject. That’s just the query language.