Preconditions
A precondition is a test an operation has to pass before it runs. With a segment as the test, the audiences that drive personalisation also decide who may act.
Segment membership
Set a precondition on the operation with a segment's key and a message. When a signed-in user calls the operation, Fóir checks their membership with the same segment evaluation that drives targeting. Segments are named groups of users defined by rules, and the same segments target content variants. People enter and leave a segment as their attributes change, so who may run the operation changes with them.
What a refused caller sees
A caller outside the segment gets a FAILED_PRECONDITION error carrying your message. With no message, the error reads "operation precondition not met". A run with no user behind it, such as one started by a schedule, fails a segment precondition.
Expression preconditions
The second kind is an expression: a rule evaluated against the operation's input and the caller's context, written with the same operators as segment rules.
Where it sits
A precondition is evaluated before the operation runs and before any usage quota, and it applies however the operation was triggered. A quota rule can be limited to a segment's members too. Requiring a second factor before an operation runs is a separate control, covered by step-up verification.
Read the detail
The operations config reference shows both kinds of precondition and the errors they return.