







Authority as Possession: Permissioned Spaces Deserve Better Than ACLs
Why Capability Trees are the right governance primitive for permissioned spaces.
Early Permission Sets · bluesky-social atproto · Discussion #4437
Progress is coming along on "Permission Sets", as part of the atproto OAuth and permission system. As with other parts of the protocol, seeing how this functionality gets implemented for ...
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permission set (#4108) · bluesky-social/atproto@f9dc9aa
* Export constants and type assertion utilities * Add permission set support to oauth provider * improve permission set parsing * Rename `PermissionSet` to `ScopePermissions` * Improve performa...
Permissioned data is a love triangle - Nick's Blog
Permissioned data is a love triangle between the user, the identities they grant permissions to, and the applications everyone uses to view controlled data. We don't need to change or reinvent the protocol to have it, because ATProtocol already supports it.
atproto made simple: granular permissions - underreacted
atproto made simple: granular permissions - underreacted
Evaluating permissioned spaces for community contexts - meri's missives
A look at Bluesky's proposed approach to private data on ATProto
Capability Trees: Sovereignty Is the Point
This piece argues that DASL introduces security risk when applied to delegations, and that by not using DASL, capability trees avoid that risk.
why they’re bad? just ask claude. it ran into the same exact things i’ve ran into. until all of these are fixed imo its perfectly acceptable for developers to ignore permission sets. they’re just not baked until they’re understandable read this transcript: claude.ai/share/dbd3e30d-958d-4ac8-a3fc…
Claude
claude.aiA deep dive on permissioned-data space access. The dials, policies, and the difference between handing out keys and revoking them.
Permissioned Data: Space Access
ngerakines.leaflet.pubwhile we're here, here's how i wish permission sets were explained to me
atproto made simple: granular permissions
underreacted.leaflet.pubI really love how this handy widget lets you quickly browse through permission sets for various existing services Pro tip for lexicon designers: This is a great way to learn from peers -- @sifa.id, @beaconbits.app, etc -- who've done the work to decompose their permissions into useful subsets 😉