> For the complete documentation index, see [llms.txt](https://selenium-4.gitbook.io/nexus-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://selenium-4.gitbook.io/nexus-docs/docs/document-services/grant-document-access/main.md).

# Grant Document Access

| Campo              | Valor                                                                         |
| ------------------ | ----------------------------------------------------------------------------- |
| **Service Domain** | Document Services                                                             |
| **BIAN Version**   | 14.0.0                                                                        |
| **Operation**      | Grant Document Access                                                         |
| **Method**         | POST                                                                          |
| **API Name**       | Document Services API                                                         |
| **Versão**         | v1.0.0                                                                        |
| **Endpoint**       | `POST /v1/document-services/document-directory/{document-directory-id}/grant` |
| **Autenticação**   | Bearer Token (OAuth 2.0 / OIDC)                                               |

***

## 1. Descrição da Operação

A operação `GrantDocumentAccess` concede acesso controlado e temporário a um documento a um utilizador (interno ou externo), definindo o nível de permissão, a janela temporal de acesso, os requisitos de segurança (autenticação multifactor, marca de água, NDA), a monitorização/auditoria da sessão, a justificação de negócio e o fluxo de aprovação do pedido de acesso.

***

## 2. Path Parameters

| Parâmetro               | Tipo   | Obrigatório | Descrição                                                                                                                    |
| ----------------------- | ------ | ----------- | ---------------------------------------------------------------------------------------------------------------------------- |
| `document-directory-id` | string | Sim         | Identificador da instância do directório de documentos que contém o documento ao qual se concede acesso (ex: `DOC-DIR-001`). |

***

## 3. Payload de Pedido (Request)

### 3.1 Exemplo

```json
{
  "documentDirectoryGrantInputRecord": {
    "documentDirectoryGrantActionRequest": "GrantDocumentAccess",
    "documentDirectoryGrantActionTaskRecord": {
      "documentDirectoryGrantActionRequest": "GrantDocumentAccess",
      "documentDirectoryGrantActionTaskReference": "DDGR-001",
      "documentDirectoryInstanceReference": "DOC-DIR-001",
      "documentDirectoryEntryReference": "DOC-ID-001",
      "documentDirectoryGrantRecord": {
        "grantType": "TEMPORARY_ACCESS",
        "grantReason": "EXTERNAL_AUDIT_REVIEW",
        "grantRequestedBy": "AUDIT_MANAGER_001",
        "grantApprovedBy": "COMPLIANCE_HEAD_001",
        "grantRequestDate": "2025-07-10T17:00:00Z",
        "accessGrantDetails": {
          "granteeInformation": {
            "granteeId": "AUDITOR-EXT-001",
            "granteeName": "Jane Smith",
            "granteeType": "EXTERNAL_AUDITOR",
            "granteeOrganization": "ABC Audit Firm",
            "granteeEmail": "jane.smith@abcaudit.com",
            "granteeRole": "SENIOR_AUDITOR",
            "authenticationMethod": "MULTI_FACTOR_AUTH"
          },
          "accessPermissions": {
            "permissionLevel": "READ_ONLY",
            "allowedActions": ["VIEW", "DOWNLOAD", "PRINT"],
            "restrictedActions": ["EDIT", "DELETE", "SHARE"],
            "downloadLimit": 1,
            "viewLimit": 5,
            "printLimit": 1,
            "accessMethod": ["WEB_PORTAL", "SECURE_API"],
            "ipRestrictions": ["192.168.1.100", "10.0.0.50"],
            "deviceRestrictions": ["REGISTERED_DEVICES_ONLY"],
            "locationRestrictions": ["AUDITOR_OFFICE", "BANK_PREMISES"]
          },
          "accessTiming": {
            "accessStartDate": "2025-07-11T09:00:00Z",
            "accessEndDate": "2025-07-15T17:00:00Z",
            "accessDuration": "P4DT8H",
            "businessHoursOnly": true,
            "timezone": "UTC-05:00",
            "maxConcurrentSessions": 1,
            "sessionTimeout": "PT30M"
          },
          "securityRequirements": {
            "requireDigitalSignature": true,
            "requireAuditLog": true,
            "requireScreenshotPrevention": true,
            "requireWatermarking": true,
            "watermarkText": "CONFIDENTIAL - AUDIT REVIEW ONLY",
            "requireNonDisclosureAgreement": true,
            "ndaReference": "NDA-AUDIT-2025-001"
          },
          "monitoringAndLogging": {
            "enableActivityMonitoring": true,
            "logAllActions": true,
            "realTimeAlerts": true,
            "screenshotDetection": true,
            "unusualActivityThreshold": "HIGH",
            "reportingFrequency": "REAL_TIME",
            "reportingRecipients": ["COMPLIANCE_HEAD_001", "SECURITY_TEAM"]
          }
        },
        "businessJustification": {
          "auditReference": "AUDIT-2025-Q2-001",
          "auditType": "REGULATORY_COMPLIANCE",
          "auditScope": "KYC_DOCUMENTATION_REVIEW",
          "regulatoryRequirement": "BANKING_REGULATION_Section_123",
          "expectedOutcome": "COMPLIANCE_VERIFICATION",
          "documentRelevance": "PRIMARY_EVIDENCE_FOR_IDENTITY_VERIFICATION"
        },
        "approvalWorkflow": {
          "approvalRequired": true,
          "approvalLevel": "SENIOR_MANAGEMENT",
          "approvalMatrix": [
            {
              "role": "COMPLIANCE_HEAD",
              "required": true,
              "approver": "COMPLIANCE_HEAD_001"
            },
            {
              "role": "SECURITY_OFFICER",
              "required": true,
              "approver": "SECURITY_OFFICER_001"
            }
          ],
          "escalationRequired": false,
          "emergencyOverride": false
        }
      }
    }
  }
}
```

### 3.2 Objecto: `documentDirectoryGrantActionTaskRecord`

| Campo                                       | Tipo   | Descrição                                                                   |
| ------------------------------------------- | ------ | --------------------------------------------------------------------------- |
| `documentDirectoryGrantActionRequest`       | string | Identificador da ação de negócio solicitada. Valor: `GrantDocumentAccess`.  |
| `documentDirectoryGrantActionTaskReference` | string | Referência única da tarefa de concessão de acesso (ex: `DDGR-001`).         |
| `documentDirectoryInstanceReference`        | string | Identificador da instância do directório de documentos (ex: `DOC-DIR-001`). |
| `documentDirectoryEntryReference`           | string | Identificador do documento ao qual se concede acesso (ex: `DOC-ID-001`).    |
| `documentDirectoryGrantRecord`              | object | Registo com os dados da concessão de acesso. Ver secção 3.3.                |

### 3.3 Objecto: `documentDirectoryGrantRecord`

| Campo                   | Tipo              | Descrição                                                                                                                                         |
| ----------------------- | ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| `grantType`             | string            | Tipo de concessão (ex: `TEMPORARY_ACCESS`).                                                                                                       |
| `grantReason`           | string            | Motivo da concessão de acesso (ex: `EXTERNAL_AUDIT_REVIEW`).                                                                                      |
| `grantRequestedBy`      | string            | Identificador de quem solicitou o acesso.                                                                                                         |
| `grantApprovedBy`       | string            | Identificador de quem aprovou o acesso.                                                                                                           |
| `grantRequestDate`      | string (ISO 8601) | Data/hora do pedido de concessão.                                                                                                                 |
| `accessGrantDetails`    | object            | Detalhes do acesso concedido. Ver secção 3.4.                                                                                                     |
| `businessJustification` | object            | Justificação de negócio do acesso (`auditReference`, `auditType`, `auditScope`, `regulatoryRequirement`, `expectedOutcome`, `documentRelevance`). |
| `approvalWorkflow`      | object            | Fluxo de aprovação do pedido (`approvalRequired`, `approvalLevel`, `approvalMatrix[]`, `escalationRequired`, `emergencyOverride`).                |

### 3.4 Objecto: `accessGrantDetails`

| Campo                  | Tipo   | Descrição                                                                                                                                                                                                                        |
| ---------------------- | ------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `granteeInformation`   | object | Dados de quem recebe o acesso (`granteeId`, `granteeName`, `granteeType`, `granteeOrganization`, `granteeEmail`, `granteeRole`, `authenticationMethod`).                                                                         |
| `accessPermissions`    | object | Nível e limites de permissão (`permissionLevel`, `allowedActions[]`, `restrictedActions[]`, `downloadLimit`, `viewLimit`, `printLimit`, `accessMethod[]`, `ipRestrictions[]`, `deviceRestrictions[]`, `locationRestrictions[]`). |
| `accessTiming`         | object | Janela temporal do acesso (`accessStartDate`, `accessEndDate`, `accessDuration`, `businessHoursOnly`, `timezone`, `maxConcurrentSessions`, `sessionTimeout`).                                                                    |
| `securityRequirements` | object | Requisitos de segurança do acesso (`requireDigitalSignature`, `requireAuditLog`, `requireScreenshotPrevention`, `requireWatermarking`, `watermarkText`, `requireNonDisclosureAgreement`, `ndaReference`).                        |
| `monitoringAndLogging` | object | Configuração de monitorização (`enableActivityMonitoring`, `logAllActions`, `realTimeAlerts`, `screenshotDetection`, `unusualActivityThreshold`, `reportingFrequency`, `reportingRecipients[]`).                                 |

***

## 4. Payload de Resposta (Response)

### 4.1 Exemplo

```json
{
  "documentDirectoryGrantOutputRecord": {
    "documentDirectoryGrantActionTaskRecord": {
      "documentDirectoryGrantActionRequest": "GrantDocumentAccess",
      "documentDirectoryGrantActionTaskReference": "DDGR-001",
      "documentDirectoryGrantActionTaskRecord": {
        "documentDirectoryInstanceRecord": {
          "documentDirectoryInstanceReference": "DOC-DIR-001",
          "documentDirectoryInstanceStatus": "Active",
          "documentDirectoryEntryRecord": {
            "documentEntryReference": "DOC-ID-001",
            "documentEntryDetails": {
              "documentId": "DOC-ID-001",
              "documentType": "IDENTIFICATION",
              "documentStatus": "VERIFIED",
              "accessGrantRecord": {
                "accessGrantId": "ACCESS-GRANT-001",
                "grantStatus": "APPROVED",
                "grantType": "TEMPORARY_ACCESS",
                "grantApprovalDate": "2025-07-10T17:30:00Z",
                "grantActivationDate": "2025-07-11T09:00:00Z",
                "grantExpiryDate": "2025-07-15T17:00:00Z",
                "granteeInformation": {
                  "granteeId": "AUDITOR-EXT-001",
                  "granteeName": "Jane Smith",
                  "granteeType": "EXTERNAL_AUDITOR",
                  "granteeOrganization": "ABC Audit Firm",
                  "authenticationRequired": "MULTI_FACTOR_AUTH"
                },
                "accessCredentials": {
                  "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
                  "tokenType": "BEARER",
                  "tokenExpiry": "2025-07-15T17:00:00Z",
                  "refreshToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
                  "accessUrl": "https://secure.bank.com/audit-portal/documents/DOC-ID-001",
                  "sessionId": "SESSION-AUDIT-001",
                  "authenticationPin": "987654"
                },
                "grantedPermissions": {
                  "permissionLevel": "READ_ONLY",
                  "allowedActions": ["VIEW", "DOWNLOAD", "PRINT"],
                  "downloadLimit": 1,
                  "downloadCount": 0,
                  "viewLimit": 5,
                  "viewCount": 0,
                  "printLimit": 1,
                  "printCount": 0,
                  "accessMethod": ["WEB_PORTAL", "SECURE_API"]
                },
                "securityMeasures": {
                  "encryptionEnabled": true,
                  "watermarkingEnabled": true,
                  "watermarkText": "CONFIDENTIAL - AUDIT REVIEW ONLY",
                  "auditLoggingEnabled": true,
                  "screenshotPrevention": true,
                  "ipRestrictions": ["192.168.1.100", "10.0.0.50"],
                  "deviceRestrictions": ["REGISTERED_DEVICES_ONLY"]
                },
                "monitoringSetup": {
                  "activityMonitoringEnabled": true,
                  "realTimeAlertsEnabled": true,
                  "logAllActionsEnabled": true,
                  "anomalyDetectionEnabled": true,
                  "reportingRecipients": ["COMPLIANCE_HEAD_001", "SECURITY_TEAM"]
                },
                "complianceRecords": {
                  "ndaAgreementSigned": true,
                  "ndaReference": "NDA-AUDIT-2025-001",
                  "ndaSignDate": "2025-07-10T17:15:00Z",
                  "regulatoryApprovalObtained": true,
                  "auditTrailReference": "AUDIT-TRAIL-GRANT-001",
                  "dataProtectionCompliance": "CONFIRMED"
                }
              }
            }
          }
        }
      }
    },
    "documentDirectoryGrantActionResponse": {
      "documentDirectoryGrantActionResponseCode": "Success",
      "documentDirectoryGrantActionResponseMessage": "Document access successfully granted to AUDITOR-EXT-001 for document DOC-ID-001",
      "documentDirectoryGrantActionResponseDetails": {
        "accessGrantId": "ACCESS-GRANT-001",
        "documentId": "DOC-ID-001",
        "granteeId": "AUDITOR-EXT-001",
        "granteeName": "Jane Smith",
        "grantStatus": "APPROVED",
        "grantActivationDate": "2025-07-11T09:00:00Z",
        "grantExpiryDate": "2025-07-15T17:00:00Z",
        "accessUrl": "https://secure.bank.com/audit-portal/documents/DOC-ID-001",
        "authenticationPin": "987654",
        "accessInstructions": [
          "Use provided PIN for initial authentication",
          "Multi-factor authentication required",
          "Access limited to specified IP addresses",
          "All activities will be monitored and logged",
          "Document contains confidential watermarking"
        ],
        "supportContact": {
          "contactName": "Document Support Team",
          "contactEmail": "docsupport@bank.com",
          "contactPhone": "+1-800-BANK-DOC",
          "supportHours": "Mon-Fri 9AM-5PM EST"
        },
        "complianceConfirmations": {
          "ndaConfirmed": true,
          "regulatoryApprovalConfirmed": true,
          "securityMeasuresActive": true,
          "monitoringActive": true
        }
      }
    }
  }
}
```

### 4.2 Objecto: `accessGrantRecord`

| Campo                                                           | Tipo              | Descrição                                                                                                                                                                              |
| --------------------------------------------------------------- | ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `accessGrantId`                                                 | string            | Identificador único da concessão de acesso (ex: `ACCESS-GRANT-001`).                                                                                                                   |
| `grantStatus`                                                   | string            | Estado da concessão (ex: `APPROVED`).                                                                                                                                                  |
| `grantType`                                                     | string            | Tipo de concessão (ex: `TEMPORARY_ACCESS`).                                                                                                                                            |
| `grantApprovalDate` / `grantActivationDate` / `grantExpiryDate` | string (ISO 8601) | Datas de aprovação, activação e expiração do acesso.                                                                                                                                   |
| `granteeInformation`                                            | object            | Dados de quem recebeu o acesso.                                                                                                                                                        |
| `accessCredentials`                                             | object            | Credenciais emitidas para o acesso (`accessToken`, `tokenType`, `tokenExpiry`, `refreshToken`, `accessUrl`, `sessionId`, `authenticationPin`).                                         |
| `grantedPermissions`                                            | object            | Permissões e contadores de utilização concedidos (`permissionLevel`, `allowedActions[]`, limites e contagens de download/visualização/impressão, `accessMethod[]`).                    |
| `securityMeasures`                                              | object            | Medidas de segurança activas (`encryptionEnabled`, `watermarkingEnabled`, `watermarkText`, `auditLoggingEnabled`, `screenshotPrevention`, `ipRestrictions[]`, `deviceRestrictions[]`). |
| `monitoringSetup`                                               | object            | Configuração de monitorização activa (`activityMonitoringEnabled`, `realTimeAlertsEnabled`, `logAllActionsEnabled`, `anomalyDetectionEnabled`, `reportingRecipients[]`).               |
| `complianceRecords`                                             | object            | Registos de conformidade (`ndaAgreementSigned`, `ndaReference`, `ndaSignDate`, `regulatoryApprovalObtained`, `auditTrailReference`, `dataProtectionCompliance`).                       |

### 4.3 Objecto: `documentDirectoryGrantActionResponse`

| Campo                                         | Tipo   | Descrição                                                                                                                                                                                                                                         |
| --------------------------------------------- | ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `documentDirectoryGrantActionResponseCode`    | string | Código do resultado da operação (ex: `Success`).                                                                                                                                                                                                  |
| `documentDirectoryGrantActionResponseMessage` | string | Mensagem descritiva do resultado da concessão de acesso.                                                                                                                                                                                          |
| `documentDirectoryGrantActionResponseDetails` | object | Detalhes do resultado: `accessGrantId`, `documentId`, `granteeId`, `granteeName`, `grantStatus`, `grantActivationDate`, `grantExpiryDate`, `accessUrl`, `authenticationPin`, `accessInstructions[]`, `supportContact`, `complianceConfirmations`. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://selenium-4.gitbook.io/nexus-docs/docs/document-services/grant-document-access/main.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
