AZ211: Custom roles from a relation that can't name their owner
roles : user from org says whose roles count on an object: only those of the object its org relation links it to, now (an assignment of another owner's role grants nothing, and authz.share refuses it). That relation must be the type's own, kept in a column or a table (not shared), and link to objects of one type: the type whose manage_roles people create the roles.
Reported when the policy is compiled: rowfence check, the editor, rowfence dev.
The mistake
authz
app role app_user
type user = app.users
type org = app.orgs
admin : user = app.org_members(org_id -> user_id)
can manage_roles = admin
type folder = app.folders
owner : user = owner_id
can view = owner or roles
roles : user from owner_orgline 9: custom roles on folder come from 'owner_org', which must be a relation of folder kept in a column or a table and linking to one type, as `org : org = org_id` [AZ211]Fixed
authz
app role app_user
type user = app.users
type org = app.orgs
admin : user = app.org_members(org_id -> user_id)
can manage_roles = admin
type folder = app.folders
org : org = org_id
owner : user = owner_id
can view = owner or roles
roles : user from org