File path sensors · GraphQL enum

AceFlags enum

Inheritance and audit flags applicable to an Access Control Entry.

Values

Enum Value Description

OBJECT_INHERIT

The entry is inherited by non-container children (Windows OI / Darwin file_inherit).

CONTAINER_INHERIT

The entry is inherited by container children (Windows CI / Darwin directory_inherit).

NO_PROPAGATE_INHERIT

Inheritance stops at direct children; grandchildren do not inherit (Windows NP / Darwin limit_inherit).

INHERIT_ONLY

The entry applies only to children via inheritance, not to the object itself (Windows IO / Darwin only_inherit).

INHERITED

The entry was placed on this object by inheritance from a parent rather than set explicitly.

SUCCESSFUL_ACCESS

For SYSTEM_AUDIT entries: generate an audit record on successful access.

FAILED_ACCESS

For SYSTEM_AUDIT entries: generate an audit record on denied access.

DEFER_INHERIT

Darwin chmod-style flag instructing the kernel to defer inheritance resolution to file-creation time.

NO_INHERIT

Darwin flag indicating the entry should not be inherited by any children regardless of other flags.

Used by

  • AclEntryMacOS type: A single macOS Access Control Entry on a file or directory.
  • AclEntryWindows type: A single Windows Access Control Entry on a file or directory.

Example

Example

"OBJECT_INHERIT"