## TL;DR

Context: On Storj, access restrictions are baked into the API key inside an access grant as caveats: operations, buckets, path prefixes, time windows.

## Steps

1. Start from a full-permission grant and carve down per tenant or per path. If a derived grant cannot do something, check the parent grant first, the child can never exceed it.

## When to use

You are seeing this: Start from a full-permission grant and carve down per tenant or per path. Use this skill when you run into "Storj access grants can only be narrowed, never widened".

## When not to use

If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.

## Versions

No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.

## Why this happens

The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.

## Edge cases

- Context: On Storj, access restrictions are baked into the API key inside an access grant as caveats: operations, buckets, path prefixes, time windows.
