# Permission group akP-vault-admin (name = filename). Gates the OpenBao # application: without a binding every Authentik user could complete an OIDC # login, so access is restricted to this group. OpenBao's own policy mapping # keys off the same group name in the ak_groups claim. application: vault