# Permission group akP-media-fafflix (name = filename). Per-service entitlement # for the adult ("fafflix") media tier: NOT bound to any application (no # `application` field), so it does not gate OIDC. It exists purely to appear in # the user's hierarchical `ak_groups` claim, which the media proxy reads to # decide whether to route/authorize the fafflix backend. attributes: {}