GRANTs and Fabric/OneLake roles — so one Loom role maps to the native permissions each platform expects. Every grant is a real POST (no mocked principals or fake grants) and the outcome lands in a live, sortable audit log below the form. Use Permissions to provision least-privilege access and to keep a reviewable trail of who was granted what.Pick a securable, a principal, and a Loom role. Loom maps the role to Unity Catalog privileges or Fabric workspace roles per the table in docs.