client.iam on a QumoClient.
listBindings
IAMBinding
createBinding
IAMBinding
removeBinding
tenantId scopes the request for session (cookie)
callers — the route names only the binding, so without a scope the
permission check resolves nothing and the call 403s. The server also
verifies the binding belongs to that tenant — for a project-scoped
binding, via the binding’s parent tenant (API-key callers may omit it;
their own tenant applies).
listTenantBindings
IAMBinding
createTenantBinding
IAMBinding
listRoles
tenantId scopes the request: session
(cookie) callers carry no tenant of their own, and an unscoped admin request
resolves to no permissions server-side, so omitting it yields 403.
Types: IAMRole