# Permission group akP-arrstack-prowlarr (name = filename). Per-app entitlement: # NOT bound to any application (no `application` field), so it does not gate OIDC. # It exists purely to appear in the user's hierarchical `ak_groups` claim, which # arrproxy reads (via oauth2-proxy X-Auth-Request-Groups) to decide whether to # mint a token allowing the prowlarr backend. attributes: {}