{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "ReviewArtifact",
  "type": "object",
  "properties": {
    "context": {
      "$ref": "#/$defs/ReviewContext"
    },
    "exploration": {
      "$ref": "#/$defs/ReviewExploration"
    },
    "preflight": {
      "type": "array",
      "items": {
        "$ref": "#/$defs/PreflightEvidence"
      }
    },
    "provenance": {
      "$ref": "#/$defs/ReviewProvenance"
    },
    "recorded": {
      "$ref": "#/$defs/RecordedReview"
    },
    "schema_version": {
      "const": "pgroles.review-artifact.v2"
    }
  },
  "additionalProperties": false,
  "required": [
    "schema_version",
    "provenance",
    "context",
    "preflight",
    "recorded",
    "exploration"
  ],
  "$defs": {
    "EvidenceCheck": {
      "type": "string",
      "enum": [
        "default_privilege_owner",
        "predefined_role_membership",
        "grantor_reachability",
        "revoke_acl_ownership",
        "plan_order_authority",
        "drop_role_safety"
      ]
    },
    "EvidenceCoverage": {
      "type": "object",
      "properties": {
        "checked_change_indices": {
          "description": "Changes considered by at least one targeted probe.",
          "type": "array",
          "items": {
            "type": "integer",
            "format": "uint",
            "minimum": 0
          }
        },
        "checks_performed": {
          "description": "Targeted probe families that actually ran. Their success does not\nestablish complete authority for a change.",
          "type": "array",
          "items": {
            "$ref": "#/$defs/EvidenceCheck"
          }
        },
        "kind": {
          "$ref": "#/$defs/EvidenceCoverageKind"
        },
        "unchecked_change_indices": {
          "description": "Changes outside every recorded probe's scope.",
          "type": "array",
          "items": {
            "type": "integer",
            "format": "uint",
            "minimum": 0
          }
        }
      },
      "additionalProperties": false,
      "required": [
        "kind",
        "checks_performed",
        "checked_change_indices",
        "unchecked_change_indices"
      ]
    },
    "EvidenceCoverageKind": {
      "type": "string",
      "enum": [
        "complete",
        "targeted"
      ]
    },
    "EvidenceStatus": {
      "type": "string",
      "enum": [
        "passed",
        "failed",
        "not_run",
        "unknown"
      ]
    },
    "ExplorationOmissionReason": {
      "type": "string",
      "enum": [
        "recorded_only_export",
        "sensitive_inputs_removed"
      ]
    },
    "ObjectType": {
      "description": "PostgreSQL object types that can have privileges granted on them.",
      "type": "string",
      "enum": [
        "table",
        "view",
        "materialized_view",
        "sequence",
        "function",
        "schema",
        "database",
        "type"
      ]
    },
    "OmissionReason": {
      "type": "string",
      "enum": [
        "sensitive_value"
      ]
    },
    "PolicyProvenance": {
      "type": "object",
      "properties": {
        "commit": {
          "type": [
            "string",
            "null"
          ]
        },
        "content_digest": {
          "description": "SHA-256 digest of the policy content, prefixed with `sha256:`.",
          "type": "string"
        }
      },
      "additionalProperties": false,
      "required": [
        "content_digest"
      ]
    },
    "PreflightCheck": {
      "type": "string",
      "enum": [
        "executor_authority",
        "role_drop_safety",
        "server_compatibility"
      ]
    },
    "PreflightEvidence": {
      "type": "object",
      "properties": {
        "actor_role": {
          "type": [
            "string",
            "null"
          ]
        },
        "check": {
          "$ref": "#/$defs/PreflightCheck"
        },
        "coverage": {
          "$ref": "#/$defs/EvidenceCoverage"
        },
        "issue_count": {
          "type": "integer",
          "format": "uint",
          "minimum": 0
        },
        "issues": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/PreflightFinding"
          }
        },
        "status": {
          "$ref": "#/$defs/EvidenceStatus"
        }
      },
      "additionalProperties": false,
      "required": [
        "check",
        "status",
        "issue_count",
        "coverage"
      ]
    },
    "PreflightFinding": {
      "type": "object",
      "properties": {
        "code": {
          "type": "string"
        },
        "message": {
          "type": "string"
        },
        "role": {
          "type": [
            "string",
            "null"
          ]
        }
      },
      "additionalProperties": false,
      "required": [
        "code",
        "message"
      ]
    },
    "Privilege": {
      "description": "PostgreSQL privilege types.",
      "type": "string",
      "enum": [
        "SELECT",
        "INSERT",
        "UPDATE",
        "DELETE",
        "TRUNCATE",
        "REFERENCES",
        "TRIGGER",
        "EXECUTE",
        "USAGE",
        "CREATE",
        "CONNECT",
        "TEMPORARY"
      ]
    },
    "RecordedChange": {
      "type": "object",
      "properties": {
        "change": {
          "$ref": "#/$defs/ReviewChange"
        },
        "index": {
          "type": "integer",
          "format": "uint",
          "minimum": 0
        },
        "omissions": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/ReviewOmission"
          }
        },
        "priority": {
          "$ref": "#/$defs/ReviewPriority"
        },
        "source": {
          "anyOf": [
            {
              "$ref": "#/$defs/ReviewChangeSource"
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "additionalProperties": false,
      "required": [
        "index",
        "priority",
        "change"
      ]
    },
    "RecordedFinding": {
      "type": "object",
      "properties": {
        "change_index": {
          "description": "The first affected change.",
          "type": [
            "integer",
            "null"
          ],
          "format": "uint",
          "minimum": 0
        },
        "change_indices": {
          "description": "Every affected change, when a finding aggregates several.",
          "type": "array",
          "items": {
            "type": "integer",
            "format": "uint",
            "minimum": 0
          }
        },
        "kind": {
          "$ref": "#/$defs/ReviewFindingKind"
        },
        "message": {
          "type": "string"
        },
        "phase": {
          "anyOf": [
            {
              "$ref": "#/$defs/ReviewPhase"
            },
            {
              "type": "null"
            }
          ]
        },
        "role": {
          "type": [
            "string",
            "null"
          ]
        },
        "severity": {
          "$ref": "#/$defs/ReviewFindingSeverity"
        }
      },
      "additionalProperties": false,
      "required": [
        "kind",
        "severity",
        "message"
      ]
    },
    "RecordedPhase": {
      "description": "One contiguous run of same-phase changes, in plan order.\n\nExecutor reachability is recorded as deltas so that artifact size tracks\nwhat changes rather than roles times phases. The state before the first\nphase is empty. The state after a phase is the previous phase's state with\nevery `removed` role deleted and then every `changed` entry inserted or\nreplaced, so the first phase's `changed` list is its complete state.\n`RecordedReview::phase_reachability` performs this fold.",
      "type": "object",
      "properties": {
        "change_indices": {
          "type": "array",
          "items": {
            "type": "integer",
            "format": "uint",
            "minimum": 0
          }
        },
        "executor_reachability_delta": {
          "description": "Change in the roles the intended executor can `SET ROLE` to.",
          "$ref": "#/$defs/ReviewReachabilityDelta"
        },
        "executor_usage_delta": {
          "description": "Change in the roles whose privileges the intended executor inherits.",
          "$ref": "#/$defs/ReviewReachabilityDelta"
        },
        "phase": {
          "$ref": "#/$defs/ReviewPhase"
        }
      },
      "additionalProperties": false,
      "required": [
        "phase",
        "change_indices",
        "executor_reachability_delta",
        "executor_usage_delta"
      ]
    },
    "RecordedReview": {
      "type": "object",
      "properties": {
        "changes": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/RecordedChange"
          }
        },
        "findings": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/RecordedFinding"
          }
        },
        "omissions": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/ReviewOmission"
          }
        },
        "phases": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/RecordedPhase"
          }
        },
        "review_fingerprint": {
          "type": "string"
        },
        "sql_preview": {
          "$ref": "#/$defs/SqlPreview"
        },
        "visual": {
          "$ref": "#/$defs/ReviewVisualGraph"
        }
      },
      "additionalProperties": false,
      "required": [
        "changes",
        "phases",
        "findings",
        "visual",
        "sql_preview",
        "review_fingerprint"
      ]
    },
    "ReviewChange": {
      "description": "A plan change with sensitive values removed. Omitted values are listed in\nthe owning recorded change's `omissions`.",
      "oneOf": [
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "create_role"
            },
            "name": {
              "type": "string"
            },
            "state": {
              "$ref": "#/$defs/ReviewRoleState"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "name",
            "state"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "create_schema"
            },
            "name": {
              "type": "string"
            },
            "owner": {
              "type": [
                "string",
                "null"
              ]
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "name"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "alter_schema_owner"
            },
            "name": {
              "type": "string"
            },
            "owner": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "name",
            "owner"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "ensure_schema_owner_privileges"
            },
            "name": {
              "type": "string"
            },
            "owner": {
              "type": "string"
            },
            "privileges": {
              "type": "array",
              "items": {
                "$ref": "#/$defs/Privilege"
              },
              "uniqueItems": true
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "name",
            "owner",
            "privileges"
          ]
        },
        {
          "type": "object",
          "properties": {
            "attributes": {
              "type": "array",
              "items": {
                "$ref": "#/$defs/ReviewRoleAttribute"
              }
            },
            "kind": {
              "type": "string",
              "const": "alter_role"
            },
            "name": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "name",
            "attributes"
          ]
        },
        {
          "type": "object",
          "properties": {
            "comment_present": {
              "type": "boolean"
            },
            "kind": {
              "type": "string",
              "const": "set_comment"
            },
            "name": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "name",
            "comment_present"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "grant"
            },
            "name": {
              "type": [
                "string",
                "null"
              ]
            },
            "object_type": {
              "$ref": "#/$defs/ObjectType"
            },
            "privileges": {
              "type": "array",
              "items": {
                "$ref": "#/$defs/Privilege"
              },
              "uniqueItems": true
            },
            "role": {
              "type": "string"
            },
            "schema": {
              "type": [
                "string",
                "null"
              ]
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "role",
            "privileges",
            "object_type"
          ]
        },
        {
          "type": "object",
          "properties": {
            "grantor": {
              "type": [
                "string",
                "null"
              ]
            },
            "kind": {
              "type": "string",
              "const": "revoke"
            },
            "name": {
              "type": [
                "string",
                "null"
              ]
            },
            "object_type": {
              "$ref": "#/$defs/ObjectType"
            },
            "privileges": {
              "type": "array",
              "items": {
                "$ref": "#/$defs/Privilege"
              },
              "uniqueItems": true
            },
            "role": {
              "type": "string"
            },
            "schema": {
              "type": [
                "string",
                "null"
              ]
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "role",
            "privileges",
            "object_type"
          ]
        },
        {
          "type": "object",
          "properties": {
            "grantee": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "const": "set_default_privilege"
            },
            "on_type": {
              "$ref": "#/$defs/ObjectType"
            },
            "owner": {
              "type": "string"
            },
            "privileges": {
              "type": "array",
              "items": {
                "$ref": "#/$defs/Privilege"
              },
              "uniqueItems": true
            },
            "scope": {
              "$ref": "#/$defs/ReviewDefaultPrivilegeScope"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "owner",
            "scope",
            "on_type",
            "grantee",
            "privileges"
          ]
        },
        {
          "type": "object",
          "properties": {
            "grantee": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "const": "revoke_default_privilege"
            },
            "on_type": {
              "$ref": "#/$defs/ObjectType"
            },
            "owner": {
              "type": "string"
            },
            "privileges": {
              "type": "array",
              "items": {
                "$ref": "#/$defs/Privilege"
              },
              "uniqueItems": true
            },
            "scope": {
              "$ref": "#/$defs/ReviewDefaultPrivilegeScope"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "owner",
            "scope",
            "on_type",
            "grantee",
            "privileges"
          ]
        },
        {
          "type": "object",
          "properties": {
            "admin": {
              "type": "boolean"
            },
            "inherit": {
              "type": "boolean"
            },
            "kind": {
              "type": "string",
              "const": "add_member"
            },
            "member": {
              "type": "string"
            },
            "role": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "role",
            "member",
            "inherit",
            "admin"
          ]
        },
        {
          "type": "object",
          "properties": {
            "grantor": {
              "type": [
                "string",
                "null"
              ]
            },
            "kind": {
              "type": "string",
              "const": "remove_member"
            },
            "member": {
              "type": "string"
            },
            "role": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "role",
            "member"
          ]
        },
        {
          "type": "object",
          "properties": {
            "from_role": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "const": "reassign_owned"
            },
            "to_role": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "from_role",
            "to_role"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "drop_owned"
            },
            "role": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "role"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "terminate_sessions"
            },
            "role": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "role"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "set_password"
            },
            "name": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "name"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "drop_role"
            },
            "name": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "name"
          ]
        }
      ]
    },
    "ReviewChangeSource": {
      "description": "The bundle document that owns a change, and the managed key it owns it by.",
      "type": "object",
      "properties": {
        "document": {
          "type": "string"
        },
        "managed_key": {
          "$ref": "#/$defs/ReviewManagedKey"
        }
      },
      "additionalProperties": false,
      "required": [
        "document",
        "managed_key"
      ]
    },
    "ReviewContext": {
      "type": "object",
      "properties": {
        "authority_graph_complete": {
          "type": "boolean"
        },
        "inspector": {
          "$ref": "#/$defs/ReviewIdentity"
        },
        "intended_executor": {
          "$ref": "#/$defs/ReviewIdentity"
        },
        "managed_scope": {
          "anyOf": [
            {
              "$ref": "#/$defs/ReviewManagedScope"
            },
            {
              "type": "null"
            }
          ]
        },
        "mode": {
          "$ref": "#/$defs/ReviewMode"
        }
      },
      "additionalProperties": false,
      "required": [
        "mode",
        "inspector",
        "intended_executor",
        "authority_graph_complete"
      ]
    },
    "ReviewDefaultPrivilegeScope": {
      "description": "Where a default-privilege rule applies; `global` is the owner-wide layer.",
      "oneOf": [
        {
          "type": "object",
          "properties": {
            "type": {
              "type": "string",
              "const": "global"
            }
          },
          "additionalProperties": false,
          "required": [
            "type"
          ]
        },
        {
          "type": "object",
          "properties": {
            "schema": {
              "type": "string"
            },
            "type": {
              "type": "string",
              "const": "schema"
            }
          },
          "additionalProperties": false,
          "required": [
            "type",
            "schema"
          ]
        }
      ]
    },
    "ReviewEdgeKind": {
      "type": "string",
      "enum": [
        "membership",
        "grant",
        "default_privilege"
      ]
    },
    "ReviewExploration": {
      "oneOf": [
        {
          "type": "object",
          "properties": {
            "reason": {
              "$ref": "#/$defs/ExplorationOmissionReason"
            },
            "status": {
              "type": "string",
              "const": "omitted"
            }
          },
          "additionalProperties": false,
          "required": [
            "status",
            "reason"
          ]
        }
      ]
    },
    "ReviewFindingKind": {
      "type": "string",
      "enum": [
        "required_role_unavailable",
        "required_role_reachability_unknown",
        "executor_loses_access",
        "membership_disconnects_role",
        "role_becomes_reachable",
        "database_preflight_required",
        "superuser_required",
        "ownership_transfer_changes_grantor"
      ]
    },
    "ReviewFindingSeverity": {
      "type": "string",
      "enum": [
        "info",
        "warning",
        "error"
      ]
    },
    "ReviewIdentity": {
      "type": "object",
      "properties": {
        "role": {
          "type": "string"
        },
        "superuser": {
          "type": [
            "boolean",
            "null"
          ]
        }
      },
      "additionalProperties": false,
      "required": [
        "role"
      ]
    },
    "ReviewManagedKey": {
      "oneOf": [
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "role"
            },
            "name": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "name"
          ]
        },
        {
          "type": "object",
          "properties": {
            "facet": {
              "$ref": "#/$defs/SchemaBindingFacet"
            },
            "kind": {
              "type": "string",
              "const": "schema_facet"
            },
            "schema": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "schema",
            "facet"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "grant"
            },
            "name": {
              "type": [
                "string",
                "null"
              ]
            },
            "object_type": {
              "$ref": "#/$defs/ObjectType"
            },
            "role": {
              "type": "string"
            },
            "schema": {
              "type": [
                "string",
                "null"
              ]
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "role",
            "object_type"
          ]
        },
        {
          "type": "object",
          "properties": {
            "grantee": {
              "type": "string"
            },
            "kind": {
              "type": "string",
              "const": "default_privilege"
            },
            "on_type": {
              "$ref": "#/$defs/ObjectType"
            },
            "owner": {
              "type": "string"
            },
            "scope": {
              "$ref": "#/$defs/ReviewDefaultPrivilegeScope"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "owner",
            "scope",
            "on_type",
            "grantee"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "membership"
            },
            "member": {
              "type": "string"
            },
            "role": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "role",
            "member"
          ]
        }
      ]
    },
    "ReviewManagedSchema": {
      "type": "object",
      "properties": {
        "bindings": {
          "type": "boolean"
        },
        "name": {
          "type": "string"
        },
        "owner": {
          "type": "boolean"
        }
      },
      "additionalProperties": false,
      "required": [
        "name",
        "owner",
        "bindings"
      ]
    },
    "ReviewManagedScope": {
      "description": "Roles and schema facets the reviewed policy manages.",
      "type": "object",
      "properties": {
        "roles": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "schemas": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/ReviewManagedSchema"
          }
        }
      },
      "additionalProperties": false,
      "required": [
        "roles",
        "schemas"
      ]
    },
    "ReviewMode": {
      "type": "string",
      "enum": [
        "authoritative",
        "additive",
        "adopt"
      ]
    },
    "ReviewNodeKind": {
      "type": "string",
      "enum": [
        "role",
        "external_principal",
        "grant_target",
        "default_privilege_target"
      ]
    },
    "ReviewOmission": {
      "type": "object",
      "properties": {
        "field": {
          "type": "string"
        },
        "reason": {
          "$ref": "#/$defs/OmissionReason"
        }
      },
      "additionalProperties": false,
      "required": [
        "field",
        "reason"
      ]
    },
    "ReviewPhase": {
      "type": "string",
      "enum": [
        "create",
        "alter",
        "grant",
        "membership_remove",
        "membership_add",
        "revoke",
        "default_privilege_revoke",
        "retire"
      ]
    },
    "ReviewPriority": {
      "description": "Conservative review priority based on change kind, not an environment-aware risk assessment.",
      "type": "string",
      "enum": [
        "High",
        "Review",
        "Informational"
      ]
    },
    "ReviewProvenance": {
      "type": "object",
      "properties": {
        "captured_at": {
          "description": "Caller-supplied RFC 3339 capture time.",
          "type": "string"
        },
        "pg_major_version": {
          "type": "integer",
          "format": "int32"
        },
        "policy": {
          "$ref": "#/$defs/PolicyProvenance"
        },
        "target_label": {
          "description": "Human-readable target label; never a connection URL.",
          "type": "string"
        },
        "tool_version": {
          "type": "string"
        }
      },
      "additionalProperties": false,
      "required": [
        "tool_version",
        "captured_at",
        "policy",
        "target_label",
        "pg_major_version"
      ]
    },
    "ReviewReachability": {
      "type": "object",
      "properties": {
        "role": {
          "type": "string"
        },
        "status": {
          "$ref": "#/$defs/ReviewReachabilityStatus"
        }
      },
      "additionalProperties": false,
      "required": [
        "role",
        "status"
      ]
    },
    "ReviewReachabilityDelta": {
      "type": "object",
      "properties": {
        "changed": {
          "description": "Roles whose status is new or different after this phase, sorted by\nrole name.",
          "type": "array",
          "items": {
            "$ref": "#/$defs/ReviewReachability"
          }
        },
        "removed": {
          "description": "Roles present after the previous phase and absent after this one,\nsorted. Never overlaps `changed`.",
          "type": "array",
          "items": {
            "type": "string"
          }
        }
      },
      "additionalProperties": false,
      "required": [
        "changed",
        "removed"
      ]
    },
    "ReviewReachabilityStatus": {
      "type": "string",
      "enum": [
        "reachable",
        "unreachable",
        "unknown"
      ]
    },
    "ReviewRoleAttribute": {
      "oneOf": [
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "login"
            },
            "value": {
              "type": "boolean"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "value"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "superuser"
            },
            "value": {
              "type": "boolean"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "value"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "createdb"
            },
            "value": {
              "type": "boolean"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "value"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "createrole"
            },
            "value": {
              "type": "boolean"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "value"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "inherit"
            },
            "value": {
              "type": "boolean"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "value"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "replication"
            },
            "value": {
              "type": "boolean"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "value"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "bypassrls"
            },
            "value": {
              "type": "boolean"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "value"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "connection_limit"
            },
            "value": {
              "type": "integer",
              "format": "int32"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "value"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "valid_until"
            },
            "value": {
              "type": [
                "string",
                "null"
              ]
            }
          },
          "additionalProperties": false,
          "required": [
            "kind"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "set_config"
            },
            "parameter": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "parameter"
          ]
        },
        {
          "type": "object",
          "properties": {
            "kind": {
              "type": "string",
              "const": "reset_config"
            },
            "parameter": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "required": [
            "kind",
            "parameter"
          ]
        }
      ]
    },
    "ReviewRoleState": {
      "type": "object",
      "properties": {
        "bypassrls": {
          "type": "boolean"
        },
        "comment_present": {
          "type": "boolean"
        },
        "config_parameters": {
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "connection_limit": {
          "type": "integer",
          "format": "int32"
        },
        "createdb": {
          "type": "boolean"
        },
        "createrole": {
          "type": "boolean"
        },
        "inherit": {
          "type": "boolean"
        },
        "login": {
          "type": "boolean"
        },
        "password_valid_until": {
          "type": [
            "string",
            "null"
          ]
        },
        "replication": {
          "type": "boolean"
        },
        "superuser": {
          "type": "boolean"
        }
      },
      "additionalProperties": false,
      "required": [
        "login",
        "superuser",
        "createdb",
        "createrole",
        "inherit",
        "replication",
        "bypassrls",
        "connection_limit",
        "comment_present",
        "config_parameters"
      ]
    },
    "ReviewVisualEdge": {
      "type": "object",
      "properties": {
        "kind": {
          "$ref": "#/$defs/ReviewEdgeKind"
        },
        "label": {
          "type": "string"
        },
        "source": {
          "type": "string"
        },
        "target": {
          "type": "string"
        }
      },
      "additionalProperties": false,
      "required": [
        "source",
        "target",
        "kind",
        "label"
      ]
    },
    "ReviewVisualGraph": {
      "description": "The simulated post-plan role graph, without role comments.",
      "type": "object",
      "properties": {
        "edges": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/ReviewVisualEdge"
          }
        },
        "meta": {
          "$ref": "#/$defs/ReviewVisualMeta"
        },
        "nodes": {
          "type": "array",
          "items": {
            "$ref": "#/$defs/ReviewVisualNode"
          }
        },
        "schema_version": {
          "type": "string"
        }
      },
      "additionalProperties": false,
      "required": [
        "schema_version",
        "meta",
        "nodes",
        "edges"
      ]
    },
    "ReviewVisualMeta": {
      "type": "object",
      "properties": {
        "collapsed": {
          "type": "boolean"
        },
        "default_privilege_count": {
          "type": "integer",
          "format": "uint",
          "minimum": 0
        },
        "grant_count": {
          "type": "integer",
          "format": "uint",
          "minimum": 0
        },
        "managed_scope": {
          "anyOf": [
            {
              "$ref": "#/$defs/ReviewManagedScope"
            },
            {
              "type": "null"
            }
          ]
        },
        "membership_count": {
          "type": "integer",
          "format": "uint",
          "minimum": 0
        },
        "role_count": {
          "type": "integer",
          "format": "uint",
          "minimum": 0
        },
        "source": {
          "$ref": "#/$defs/ReviewVisualSource"
        }
      },
      "additionalProperties": false,
      "required": [
        "source",
        "role_count",
        "grant_count",
        "default_privilege_count",
        "membership_count",
        "collapsed"
      ]
    },
    "ReviewVisualNode": {
      "description": "A graph node. Role comments are never recorded, so there is no comment\nfield to populate.",
      "type": "object",
      "properties": {
        "id": {
          "type": "string"
        },
        "kind": {
          "$ref": "#/$defs/ReviewNodeKind"
        },
        "label": {
          "type": "string"
        },
        "login": {
          "type": [
            "boolean",
            "null"
          ]
        },
        "managed": {
          "type": [
            "boolean",
            "null"
          ]
        },
        "privileges": {
          "type": "array",
          "items": {
            "type": "string"
          }
        }
      },
      "additionalProperties": false,
      "required": [
        "id",
        "label",
        "kind"
      ]
    },
    "ReviewVisualSource": {
      "type": "string",
      "enum": [
        "desired",
        "current"
      ]
    },
    "SchemaBindingFacet": {
      "type": "string",
      "enum": [
        "owner",
        "bindings"
      ]
    },
    "SqlOmissionReason": {
      "type": "string",
      "enum": [
        "sensitive_changes"
      ]
    },
    "SqlPreview": {
      "oneOf": [
        {
          "type": "object",
          "properties": {
            "sql": {
              "type": "string"
            },
            "status": {
              "type": "string",
              "const": "available"
            }
          },
          "additionalProperties": false,
          "required": [
            "status",
            "sql"
          ]
        },
        {
          "type": "object",
          "properties": {
            "reason": {
              "$ref": "#/$defs/SqlOmissionReason"
            },
            "sensitive_change_indices": {
              "type": "array",
              "items": {
                "type": "integer",
                "format": "uint",
                "minimum": 0
              }
            },
            "status": {
              "type": "string",
              "const": "omitted"
            }
          },
          "additionalProperties": false,
          "required": [
            "status",
            "reason",
            "sensitive_change_indices"
          ]
        }
      ]
    }
  }
}
