All !grant
policies should be loaded into the root
branch.
A !grant
is the same as adding a member to a security group in Active Directory in Conjur's policy-as-code.
- !grant
role: !group GroupName
member: !user UserName
- !grant
role: !group GroupName
members:
- !user UserName
- !host HostName
- !group AnotherGroupName
- User groups
- Admins
- Auditors
- Vault Conjur Synchronizer consumer groups
- Vault Conjur Synchronizer admin groups
- Authenticator groups