---
title: AccessMask enum | Wartiva GraphQL API
description: A single permission bit in an ACL access mask, harmonized across Windows and Darwin to NTFS-style vocabulary. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/types/access-mask.html
updated: 2026-10-07
---

File path sensors · GraphQL enum

# `AccessMask` enum

A single permission bit in an ACL access mask, harmonized across Windows and Darwin to NTFS-style vocabulary.

## Values

| Enum Value | Description |
|---|---|
| `FILE_READ_DATA` | Read the file's primary data stream (or, on directories, list contents). |
| `FILE_WRITE_DATA` | Write to (overwrite portions of) the file's primary data stream, or create files in a directory. |
| `FILE_APPEND_DATA` | Append data to the file, or create subdirectories within a directory. |
| `FILE_READ_EA` | Read extended attributes / named streams metadata. |
| `FILE_WRITE_EA` | Write extended attributes / named streams metadata. |
| `FILE_EXECUTE` | Execute the file (Darwin) or traverse the directory (Windows / Darwin). |
| `FILE_DELETE_CHILD` | On a directory, delete a file or subdirectory within it even if the child denies DELETE. |
| `FILE_READ_ATTRIBUTES` | Read the file's basic attributes (timestamps, size, mode bits). |
| `FILE_WRITE_ATTRIBUTES` | Modify the file's basic attributes. |
| `DELETE` | Delete the object itself. |
| `READ_CONTROL` | Read the object's security descriptor (owner, DACL). |
| `WRITE_DAC` | Modify the object's discretionary access-control list. |
| `WRITE_OWNER` | Change the object's owner. |
| `SYNCHRONIZE` | Use the object as a synchronization primitive (Windows). Has no equivalent semantics on Darwin and is preserved verbatim. |
| `ACCESS_SYSTEM_SECURITY` | Modify the object's system ACL / audit policy (privileged on Windows). |
| `MAXIMUM_ALLOWED` | Windows-only sentinel that resolves at access time to the maximum permissions the subject is allowed. |
| `GENERIC_ALL` | Generic bit that resolves to the full set of specific access rights for this object class. |
| `GENERIC_EXECUTE` | Generic execute / traverse bit (resolves to a subset of the specific bits). |
| `GENERIC_WRITE` | Generic write bit (resolves to a subset of the specific bits). |
| `GENERIC_READ` | Generic read bit (resolves to a subset of the specific bits). |

## Used by

- [`AclEntryMacOS`](https://wartiva.com/api-docs/types/acl-entry-mac-os.html) type: A single macOS Access Control Entry on a file or directory.
- [`AclEntryWindows`](https://wartiva.com/api-docs/types/acl-entry-windows.html) type: A single Windows Access Control Entry on a file or directory.

## Example

### Example

```json
"FILE_READ_DATA"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
