> For the complete documentation index, see [llms.txt](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/developers/api/query-builder/terminology.md).

# Query Builder Terminology

Graph search concepts for working with the query builder

## Entity (Node)

An entity, also referred to as a node, represents an authorization, data, or identity object discovered by Veza. It can be a concrete external named entity, such as `AwsIamPolicy` or `OktaUser`, or an edge aggregation node created by Veza for visualization and service purposes.

Entities, within the context of the Query Builder API, are the building blocks that represent various authorization, data, and identity objects discovered by Veza. They are used to construct queries, workflows, and Access Graph searches.

Entities encompass a wide range of elements, including identities, local users, data resources, identity domains, and IAM or RBAC elements such as security groups, policies, and roles.

When constructing queries, you will typically specify the source and destination entity types, such as `Okta User to AWS S3 Bucket` or `Google User to Google Group`, along with specific constraints on those entity types.

The Query Builder API offers top-level **Entity Type Groupings** such as *User* and *Resource*, providing an easy way to select and constrain all entities belonging to a particular supertype.

## Entity Attribute

An entity attribute is a key-value pair associated with a specific entity type. These attributes carry rich metadata, enabling granular filters and search conditions.

Veza will add certain properties such as `name`, `is human`, or `full admin` during parsing. Other attributes such as `mfa_enabled` and `is_encrypted` can be directly ingested from the provider.

## Entity Type

An entity type represents the final and precise specification of a node's category in an external system. Examples of external entity types include `AwsIamUser`, or `S3Bucket`.

## Entity Type Grouping

An entity type grouping, or supertype, provides a top-level label to search for multiple entity types in a single query, such as `User` or `Resource`. Constraints can apply to an entity type grouping as if it were a single entity.

Supertypes are groupings of entities in the graph, allowing the specification of a "one of" style constraint among different concrete node types. A node type can be a member of one or more supertypes, and a supertype can contain concrete node types as well as other supertypes.

## Effective and System Permissions

*Raw* or *System* permissions refer to individual privileges defined in the provider's internal terms, for example, AWS IAM `s3:BucketDelete`.

*Effective Permissions* represent the canonical C/R/U/D equivalents of system permissions. For example, `MetadataWrite`, `DataRead`, `NonData`.

Note: When filtering by permission, you must specify the type of permission. Effective and system permissions cannot both be specified for the same query. If a search does not involve privileged relationships to resources, the permissions filter has no effect (e.g., User->Policy search).

## Tags

Veza supports two types of tags:

1. *Veza Tags*: These are key or key-value pairs that users add to Access Graph entities.
2. Provider-Specific Tags: Veza also discovers tags specific to providers, such as *AWS tags* and *Google Cloud labels*.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.veza.com/4yItIzMvkpAvMVFAamTf/developers/api/query-builder/terminology.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
