# feat(grant): positional provider:handle grantees + repo clone URL (COR-699)

`b935e81`→[main](/content/gh/entireio/cli/commits/main/index.html)·  toothbrush·2w ago·7 files·+309 added/-228 removed

Address grantees as `github:alice` instead of --provider/--provider-user-id

flag soup: `grant {org,project,repo} add/remove` now take a positional `<target> <grantee>`, resolving the handle to its provider user id via the control plane (new resolveGranteeProvider). remove also accepts an account ULID for the typed-id revoke route. Show the entire:// clone URL in `repo get`.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

## Sessions

### 3018b0b38bf3
View transcript

## Changes

7

- cmd/entire/cli
  
  - Mgrant.go+121/-172
  
  - Mgrant_test.go-35
  
  - Mgrant_wiring_test.go+47/-20
  
  - Mrepo.go+17/-1
  
  - Mrepo_test.go+35
  
  - Mresolveref.go+40
  
  - Mresolveref_test.go+49

```go
import (
	"context"
	"errors"
	"fmt"

"github.com/spf13/cobra"
)

// validateGrantGranteeType rejects grantee kinds the control plane no longer
// accepts when granting. A grant resolves to an account (from the provider
// identity), so "account" is the only valid kind ("" means the default,
// account). org/team granting was dropped server-side (COR-561) and the
// generated client enum is account-only, so catch it here with a clear message
// instead of an opaque enum-encoding error.
func validateGrantGranteeType(granteeType string) error {
	switch granteeType {
	case "", "account":
		return nil
	default:
		return fmt.Errorf("invalid --grantee-type %q: only \"account\" is supported", granteeType)
	}
}

// newGrantCmd is the hidden `entire grant` command group: manage access
// grants and org membership on the Entire control plane. Org, project, and
// repo each support add / list / remove. Surfaced via `entire labs`.
//
// Grantees are addressed by their identity provider + provider user id
// (e.g. --provider github --provider-user-id 12345), matching the control
// plane's grant model. Handle-based addressing is a follow-up.
// Grantees are addressed by a provider-qualified handle (e.g. github:alice),
// which the CLI resolves to the provider account behind the scenes. `remove`
// also accepts an account ULID to revoke a grant by id. Targets (org, project,
// repo) are addressed by name or ULID.
func newGrantCmd() *cobra.Command {
	cmd := &cobra.Command{
		Use:    "grant",
	}
	return cmd
}

// ... function implementations continued...
```

### Additional Details
- New features to address grantees.
- Improved command usages in granting processes.
