Glossary
The vocabulary the SDK uses to describe its world. Where a term is overloaded in the wider Laravel, UI5 or SAP ecosystem, this page records the SDK's specific meaning.
A
Ability
A semantic permission — the atomic unit of authorization. Belongs to exactly one artifact and carries an AbilityType. Stored in sdk_abilities.
AbilityType
The enum that categorises an ability. Four values are in use: Access (structural — may you open this at all), See (UX visibility), Act (a backend-validated operation) and Read (an OData entity set). Integer-backed; the 0 slot is vacant, left by a retired Use type. See permission levels.
Action
The only way anything is written. An Ui5Action artifact with a typed handler and a form request, dispatched over ui5/api/…. OData is read-only in LaravelUi5, so there is no other write path. See mutating actions.
Actor
The partner authorization is evaluated as. Under impersonation this differs from the principal. Carried on the SdkContext; read it with $context->actor(), never from Auth::user().
Actor slot value
A slot value a person carries — Alice works in EUR, Bob in CHF. Stored in sdk_slot_assignments, one value per actor and slot, no history. See actor slot values.
Artifact
A registered UI5 entity: application, library, card, report, tile, analytic tile, dashboard, dashboard group, action, resource, dialog, value help, analytics set, analytic card, chart. Identified by a namespace string, catalogued in sdk_artifacts, and the unit an ability belongs to.
B
BusinessTransaction
The seal an SDK action handler works inside. The dispatcher opens a database transaction, hands the handler the transaction object, and maps commit or rollback to the business outcome. A handler reports through it rather than committing on its own.
C
Capability mini-app
A standalone app whose presence in a person's world is gated by one Access ability. The SDK's preferred unit of granularity: if not everyone may use it, it is its own app. Route-gating inside an app is explicitly retired. See capability mini-apps.
CmdK
The command palette — the global search surface in the LeanShell, opened with Cmd+K. Discovers; does not decide. See global search.
Concept
A LUX Weave identity: this is a Partner, declared with #[Concept] on the class that owns the model. Two modules that name the same concept can navigate to each other without either knowing the other exists. See Weave.
ConceptEntry
The single canonical front door to a concept — at most one per concept. "To open a Partner, go here." Declared with #[ConceptEntry].
Context
See SdkContext. In the UI5 client, Context also means something else: the control that binds an element to a help topic by UUID.
Customizing
Controlled vocabularies declared in code and projected into the database by ui5:sync — partner roles, relationship types, address providers. The table is owned entirely by the code: sync deletes any row nobody declared. Distinct from tailoring. See reference catalogs.
D
Dashboard
A composition of tiles and cards, declared as an artifact and rendered from a manifest the client walks. Contributions from other modules arrive through Weave.
Delegation
A row in sdk_delegations permitting one partner to impersonate another, for a bounded window.
Discovery
Finding artifacts that match a query. The discovery layer finds; the Security domain decides what may be seen; the constraint is applied in the query, never in PHP afterwards. See visibility and CmdK.
E — H
Explain
The verbose form of ability resolution: every granted ability carries its source — which role or group produced it, from which assignment row, valid over which window. See the Explain CLI.
Exportable
A table-shaped dataset an app can hand over as a download — filename, headings, count, rows. Named in the SDK's own terms so no spreadsheet library reaches a signature. See table export.
Group
A structural bundle of roles and abilities, granted as one unit. Stored in sdk_groups.
Help topic
A documentation page identified by a UUID, authored at doc/<uuid>/<locale>.md inside the owning module, compiled by ui5:help. See the help concept.
I — L
Impersonation
Acting inside another partner's context while the original principal is preserved for audit. Always lands on the Launchpad, never on a gated app. See impersonation.
Intent
A structured request the client sends to the server for a decision — open this artifact, navigate there, start impersonating. Authorized server-side, then handled. Seven ship with the SDK. See intent dispatch.
Launchpad
The shipped landing app: the module home, the safe landing for impersonation, and the default post-login destination. Auth-only, no #[Access] gate — by design. See the Launchpad.
LeanShell
The SDK's runtime container around a UI5 app: navigation, context, search, intent dispatch, help and global dialogs. See the shell overview.
LoginRecord
The SDK's own DTO for a partner's login state, so nothing above the seam names your User model. See login.
LUX Weave
The cross-vendor composition layer — #[Concept], #[ConceptEntry], #[Weave] — that lets modules from different authors navigate into and contribute to each other. See Weave.
M — P
Manifest
An artifact's JSON descriptor. The SDK extracts ability declarations from it; Core injects the OData data source into it. Generated — edit the source project, not the output.
Module
A coherent set of artifacts that ship together, listed in ui5.modules. Modules are runtime-only: sdk_artifacts stores artifacts by namespace, with no foreign key to a module.
Partner
A business actor — a person, an organisation or a department, all in sdk_partners. The SDK's generalisation over user / customer / contact / account. Authorization is about partners, not user accounts. See partners.
Principal
The authenticated identity — who signed in. Distinct from the actor, which is whose permissions apply. They differ only under impersonation.
R — S
Read gate
The #[Read] ability on an OData entity set: may this actor read this set at all. Default-open — a set without the attribute is unaffected. Separate from scoping, which answers which rows. See the read gate.
Role
A named bag of abilities, stored in sdk_roles, linked through sdk_ability_role. Granted to a partner for a window, optionally in a context. Not to be confused with a partner role (customer, supplier), which is business master data in sdk_partner_roles.
Role scope
The context_type / context_id pair on a role assignment: this role, but only for that project. The role says who, the scope says which. See role scope.
Scope (settings)
The level a setting applies at, most general to most specific: Platform, Installation, Tenant, Site, User. Resolution walks from specific to general and the first answer wins. See scope precedence.
Scoping (entity sets)
Restricting which rows an actor sees, applied in the query by a scope applier. Distinct from the read gate. See scoped entity sets.
SdkContext
The immutable per-request context: artifact, tenant, actor, principal, locale, timestamp, the ability snapshot and the settings. Every authorization decision evaluates against one explicitly. Bound by the middleware at the request edge.
Setting
A scoped configuration value for one artifact, stored as JSON in sdk_settings and type-validated separately from storage. Answers how is this artifact configured, where a slot answers in what context am I working. See reading and writing settings.
Slot
A declared need for a contextual value — "I need to know the currency" — declared with #[Slot] on a module and resolved per request through the chain Request → Actor → Composition → Setting. Seven scalar types, no arrays, no models. See actor slot values.
Snapshot
The compact form of ability resolution: a flat [type => [ability => bool]] map. What the runtime uses; explain is its verbose sibling.
Sync
The pipeline that persists declarations into the database — seven workers, fixed order, idempotent, --dry capable. See the sync pipeline.
System actor
The installation's single non-human partner, the platform owner, stamped as the writer on actor-less writes. Created by ui5:intake before the first sync. See the system actor.
T — Z
Tailoring
The values — who holds which role, which override is set. Written at runtime by a consultant or an administrator. The counterpart of Customizing, which is the vocabulary. They never share a table.
Tenant
The top-level scoping unit. In LaravelUi5 a tenant is a database: one tenant, one schema, no row-level tenant filtering. Always resolved explicitly through a resolver. See tenancy.
Tile
A dashboard widget artifact. An analytic tile is the single-metric variant — what earlier releases called a KPI, and the name you will still find in old material.
UUID
The identity of a help topic. Used because file paths and titles change under refactoring and UUIDs do not. Renaming a topic must never change its UUID.
Value help
A picker dialog answering which one? — an SDK-owned artifact type with named scopes, each scope resolving to an entity set gated by its own read gate. See value helps.