Skip to content

Glossary ​

The vocabulary the SDK uses to describe its world. Where a term is overloaded in the wider Laravel, UI5 or SAP ecosystem, this page records the SDK's specific meaning.

A ​

Ability ​

A semantic permission — the atomic unit of authorization. Belongs to exactly one artifact and carries an AbilityType. Stored in sdk_abilities.

AbilityType ​

The enum that categorises an ability. Four values are in use: Access (structural — may you open this at all), See (UX visibility), Act (a backend-validated operation) and Read (an OData entity set). Integer-backed; the 0 slot is vacant, left by a retired Use type. See permission levels.

Action ​

The only way anything is written. An Ui5Action artifact with a typed handler and a form request, dispatched over ui5/api/…. OData is read-only in LaravelUi5, so there is no other write path. See mutating actions.

Actor ​

The partner authorization is evaluated as. Under impersonation this differs from the principal. Carried on the SdkContext; read it with $context->actor(), never from Auth::user().

Actor slot value ​

A slot value a person carries — Alice works in EUR, Bob in CHF. Stored in sdk_slot_assignments, one value per actor and slot, no history. See actor slot values.

Artifact ​

A registered UI5 entity: application, library, card, report, tile, analytic tile, dashboard, dashboard group, action, resource, dialog, value help, analytics set, analytic card, chart. Identified by a namespace string, catalogued in sdk_artifacts, and the unit an ability belongs to.

B ​

BusinessTransaction ​

The seal an SDK action handler works inside. The dispatcher opens a database transaction, hands the handler the transaction object, and maps commit or rollback to the business outcome. A handler reports through it rather than committing on its own.

C ​

Capability mini-app ​

A standalone app whose presence in a person's world is gated by one Access ability. The SDK's preferred unit of granularity: if not everyone may use it, it is its own app. Route-gating inside an app is explicitly retired. See capability mini-apps.

CmdK ​

The command palette — the global search surface in the LeanShell, opened with Cmd+K. Discovers; does not decide. See global search.

Concept ​

A LUX Weave identity: this is a Partner, declared with #[Concept] on the class that owns the model. Two modules that name the same concept can navigate to each other without either knowing the other exists. See Weave.

ConceptEntry ​

The single canonical front door to a concept — at most one per concept. "To open a Partner, go here." Declared with #[ConceptEntry].

Context ​

See SdkContext. In the UI5 client, Context also means something else: the control that binds an element to a help topic by UUID.

Customizing ​

Controlled vocabularies declared in code and projected into the database by ui5:sync — partner roles, relationship types, address providers. The table is owned entirely by the code: sync deletes any row nobody declared. Distinct from tailoring. See reference catalogs.

D ​

Dashboard ​

A composition of tiles and cards, declared as an artifact and rendered from a manifest the client walks. Contributions from other modules arrive through Weave.

Delegation ​

A row in sdk_delegations permitting one partner to impersonate another, for a bounded window.

Discovery ​

Finding artifacts that match a query. The discovery layer finds; the Security domain decides what may be seen; the constraint is applied in the query, never in PHP afterwards. See visibility and CmdK.

E — H ​

Explain ​

The verbose form of ability resolution: every granted ability carries its source — which role or group produced it, from which assignment row, valid over which window. See the Explain CLI.

Exportable ​

A table-shaped dataset an app can hand over as a download — filename, headings, count, rows. Named in the SDK's own terms so no spreadsheet library reaches a signature. See table export.

Group ​

A structural bundle of roles and abilities, granted as one unit. Stored in sdk_groups.

Help topic ​

A documentation page identified by a UUID, authored at doc/<uuid>/<locale>.md inside the owning module, compiled by ui5:help. See the help concept.

I — L ​

Impersonation ​

Acting inside another partner's context while the original principal is preserved for audit. Always lands on the Launchpad, never on a gated app. See impersonation.

Intent ​

A structured request the client sends to the server for a decision — open this artifact, navigate there, start impersonating. Authorized server-side, then handled. Seven ship with the SDK. See intent dispatch.

Launchpad ​

The shipped landing app: the module home, the safe landing for impersonation, and the default post-login destination. Auth-only, no #[Access] gate — by design. See the Launchpad.

LeanShell ​

The SDK's runtime container around a UI5 app: navigation, context, search, intent dispatch, help and global dialogs. See the shell overview.

LoginRecord ​

The SDK's own DTO for a partner's login state, so nothing above the seam names your User model. See login.

LUX Weave ​

The cross-vendor composition layer — #[Concept], #[ConceptEntry], #[Weave] — that lets modules from different authors navigate into and contribute to each other. See Weave.

M — P ​

Manifest ​

An artifact's JSON descriptor. The SDK extracts ability declarations from it; Core injects the OData data source into it. Generated — edit the source project, not the output.

Module ​

A coherent set of artifacts that ship together, listed in ui5.modules. Modules are runtime-only: sdk_artifacts stores artifacts by namespace, with no foreign key to a module.

Partner ​

A business actor — a person, an organisation or a department, all in sdk_partners. The SDK's generalisation over user / customer / contact / account. Authorization is about partners, not user accounts. See partners.

Principal ​

The authenticated identity — who signed in. Distinct from the actor, which is whose permissions apply. They differ only under impersonation.

R — S ​

Read gate ​

The #[Read] ability on an OData entity set: may this actor read this set at all. Default-open — a set without the attribute is unaffected. Separate from scoping, which answers which rows. See the read gate.

Role ​

A named bag of abilities, stored in sdk_roles, linked through sdk_ability_role. Granted to a partner for a window, optionally in a context. Not to be confused with a partner role (customer, supplier), which is business master data in sdk_partner_roles.

Role scope ​

The context_type / context_id pair on a role assignment: this role, but only for that project. The role says who, the scope says which. See role scope.

Scope (settings) ​

The level a setting applies at, most general to most specific: Platform, Installation, Tenant, Site, User. Resolution walks from specific to general and the first answer wins. See scope precedence.

Scoping (entity sets) ​

Restricting which rows an actor sees, applied in the query by a scope applier. Distinct from the read gate. See scoped entity sets.

SdkContext ​

The immutable per-request context: artifact, tenant, actor, principal, locale, timestamp, the ability snapshot and the settings. Every authorization decision evaluates against one explicitly. Bound by the middleware at the request edge.

Setting ​

A scoped configuration value for one artifact, stored as JSON in sdk_settings and type-validated separately from storage. Answers how is this artifact configured, where a slot answers in what context am I working. See reading and writing settings.

Slot ​

A declared need for a contextual value — "I need to know the currency" — declared with #[Slot] on a module and resolved per request through the chain Request → Actor → Composition → Setting. Seven scalar types, no arrays, no models. See actor slot values.

Snapshot ​

The compact form of ability resolution: a flat [type => [ability => bool]] map. What the runtime uses; explain is its verbose sibling.

Sync ​

The pipeline that persists declarations into the database — seven workers, fixed order, idempotent, --dry capable. See the sync pipeline.

System actor ​

The installation's single non-human partner, the platform owner, stamped as the writer on actor-less writes. Created by ui5:intake before the first sync. See the system actor.

T — Z ​

Tailoring ​

The values — who holds which role, which override is set. Written at runtime by a consultant or an administrator. The counterpart of Customizing, which is the vocabulary. They never share a table.

Tenant ​

The top-level scoping unit. In LaravelUi5 a tenant is a database: one tenant, one schema, no row-level tenant filtering. Always resolved explicitly through a resolver. See tenancy.

Tile ​

A dashboard widget artifact. An analytic tile is the single-metric variant — what earlier releases called a KPI, and the name you will still find in old material.

UUID ​

The identity of a help topic. Used because file paths and titles change under refactoring and UUIDs do not. Renaming a topic must never change its UUID.

Value help ​

A picker dialog answering which one? — an SDK-owned artifact type with named scopes, each scope resolving to an entity set gated by its own read gate. See value helps.