The object id.
An object type the app's fragment declares (or company_module for the app's company anchor).
The relation.
The subject id.
OptionalsubjectFor a userset subject, the relation on the subject type.
user for a login subject, company_module for the anchor, or a userset's type.
One relation tuple:
objectType:objectId#relation@subjectType:subjectId.