# users One file per human, `.yaml`, listing the `akR-*` roles they hold: ```yaml # Human user jane (username = filename). The account itself is not managed here # (humans come from LDAP sync / invite); only its role membership is. roles: - akR-media-adult ``` The account is looked up by username and must already exist — nothing here creates users. A role that has no `config/roles/.yaml` fails the plan. **Naming a role here makes Terraform authoritative over that role's entire member list**: members added by hand in the Authentik UI for that role are removed on the next apply. Roles no user file names are left untouched.