Optional ReadonlydomainThe ID of the domain unit whose projects receive the grant, or '/root' for the domain's root domain unit. Other domain unit paths are not supported.
Optional ReadonlyincludeWhether projects in domain units below the specified domain unit also receive the grant.
Optional ReadonlyprojectThe project designation (OWNER or CONTRIBUTOR) whose members receive the grant.
Configuration for granting an authorization policy to project members via a project grant filter, instead of to named users or groups. Required by DataZone for policies such as CREATE_FORM_TYPE that are gated on project membership rather than a specific principal.