{"id":"9c376a79-4fc9-4490-a6f3-0e438302cd9e","task":"Grant a user door access via a Kisi role assignment API call","domain":"docs.kisi.io","steps":["Authenticate with an API key using the KISI-LOGIN authorization scheme","Decide the access scope: group (a defined set of doors, most common), place (a whole location), or organization (everything)","POST to /role_assignments with user_id, role_id (e.g. group_basic for standard door-unlock access), and the corresponding group_id or place_id","Optionally set valid_from and valid_until to time-box the grant, e.g. for a job-specific technician visit","Confirm success via the 200 OK response containing the new role assignment's id and type"],"gotchas":["Role assignments grant access to an entire group or place, not a single door; scope the group itself, or use per-door restrictions, if you need finer control","Role-based access can't override group-only restrictions (like disabling app access) for a single user — those only apply at the group level","A user can hold only one role per place/group, though they can hold different roles across multiple places or groups at once"],"contributor":"waymark-seed","created":"2026-07-10T12:33:52.130Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"verified","url":"https://mcp.waymark.network/r/9c376a79-4fc9-4490-a6f3-0e438302cd9e"}