diff --git a/pom.xml b/pom.xml
index a7bff33cf..7bf4f3f55 100644
--- a/pom.xml
+++ b/pom.xml
@@ -4,7 +4,7 @@
com.authlete
authlete-java-common
- 4.41-SNAPSHOT
+ 4.41-SNAPSHOT-INTERNAL
jar
${project.groupId}:${project.artifactId}
diff --git a/src/main/java/com/authlete/common/api/AccessRight.java b/src/main/java/com/authlete/common/api/AccessRight.java
index 589738723..46f23b54d 100644
--- a/src/main/java/com/authlete/common/api/AccessRight.java
+++ b/src/main/java/com/authlete/common/api/AccessRight.java
@@ -49,8 +49,10 @@ public enum AccessRight
MODIFY_CLIENT(true, true, VIEW_CLIENT),
/** can view the details of this service */
VIEW_SERVICE(false, true, VIEW_CLIENT),
+ /** can use the introspection endpoint */
+ USE_INTROSPECTION(false, true),
/** can use the non-destructive service API calls (auth endpoint, token endpoint, etc.) */
- USE_SERVICE(false, true, VIEW_SERVICE, VIEW_CLIENT),
+ USE_SERVICE(false, true, USE_INTROSPECTION, VIEW_SERVICE, VIEW_CLIENT),
/** can create new clients on this service */
CREATE_CLIENT(false, true, USE_SERVICE, VIEW_SERVICE, MODIFY_CLIENT, VIEW_CLIENT),
/** can modify this service */
@@ -59,6 +61,8 @@ public enum AccessRight
VIEW_DEFAULT_SERVICE(false, false),
/** can create additional services */
CREATE_SERVICE(false, false, VIEW_DEFAULT_SERVICE),
+ /** can view audit logs */
+ VIEW_AUDIT_LOG(false, false),
/** can delete a specific service */
DELETE_SERVICE(false, true),
/** can call administrative functions on the Authlete server */