# Allow management of policies (create, update, delete, list, and read) path "sys/policies/acl/*" { capabilities = ["create", "update", "delete", "read", "list"] } # Allow listing of available policies path "sys/policies/acl" { capabilities = ["read", "list"] }