canva-enterprise-rbac
Installation
SKILL.md
Canva Capability-Aware Authorization
Overview
Use Canva scopes and capabilities as provider inputs to your own authorization decision. Do not equate OAuth consent with tenant role, resource ownership, feature entitlement, or approval to process content.
Prerequisites
- Application roles, actions, tenants, and deny-by-default policy
- Current explicit Canva scopes and capability response contract
- Resource ownership and data-classification checks
Instructions
Step 1: Define the decision tuple
Name subject, tenant, application role, action, resource, environment, requested Canva operation, and data class.