GraphQL: "Forbidden access" for relational field

I am still getting the hang of GraphQL in v4, but is this for custom resolvers, or is this for content types generated within the content type builder?

I have to look into it, even though the controllers and resolvers are decoupled, you might have to give it public access in setting > roles > public.