capability property
Optional filter — only entries whose EFFECTIVE capability set includes this
capability (the role's full ceiling for capabilities: {scope: ceiling}, nothing
for none, and for listed the ceiling ∩ the non-additive grants plus the
additive grants). Combined with resource, the capability must be held at a
qualifier related to that resource by direction.
Implementation
final Capability? capability;