# Permission group akP-arrstack-user (name = filename). Front-door access to the # arrstack application: bound to the arrstack oauth2 app, so only members of this # group (or any role that nests it) can complete OIDC to the front door. application: arrstack