The Explain CLI
ui5:explain answers why a partner can or can't do something: for one app, one partner and one moment.
php artisan ui5:explain --app=com.laravelui5.partners --partner=2
php artisan ui5:explain --app=com.laravelui5.partners --partner=2 --at="2026-01-01 08:00:00"| Option | Holds |
|---|---|
--app | the app's namespace (required) |
--partner | the partner's id (required) |
--at | the moment to evaluate, in any form Carbon can parse; defaults to now |
Reading the output
A run against the SDK's Partners app, trimmed. Sections come in the order access, act, see, read:
App: com.laravelui5.partners
Partner: #2 (Alice Berger)
At: 2026-09-11 16:56:04
--------------------------------------------------------------------------------
ACCESS
----------------------------------------
...
ACT
----------------------------------------
act.addGroup ✅ GRANTED
via GROUP group=it_admins 2026-07-20 09:52:01 → 9999-12-31 23:59:59
via ROLE role=local_admin assignment=#2 2026-07-20 09:52:01 → 9999-12-31 23:59:59
act.addGroupAbility ❌ DENIED
SEE
----------------------------------------
see.com.laravelui5.partners.view.Groups.addAbilityBtn ❌ DENIED
...Every ability of the app appears as GRANTED or DENIED, grouped by type and led by Access — the one that decides whether the app opens at all, and therefore the first question worth asking. A granted ability lists every source that grants it, whether a role, a group or a direct grant, with the assignment id of the row that confers it and the window in which it holds. Several sources can grant the same ability, so taking one away leaves the others.
With --at you look at another moment. A moment before a grant started shows that ability as DENIED (Time-Aware Grants).
Following a grant to its row
The assignment=#… on a source is the primary key of the row in sdk_ability_assignments, sdk_role_assignments or sdk_group_assignments that confers the grant — which is what turns "they have it through local_admin" into something you can act on. Ending a grant means delineating that row, not deleting it (Time-Aware Grants).
Before SDK 1.2.0
Earlier releases listed only See and Act, so Access and Read never appeared — the command could not answer whether someone may open an app, which is the question most people run it for. The assignment id was absent too. If you are on such a release, read the role and group names and look the rows up by hand.
Resolution Engine describes the explain mode behind the command.