diff --git a/policies/identity_admin_policy.hcl b/policies/identity_admin_policy.hcl index 3edb6ea..5d2ded5 100644 --- a/policies/identity_admin_policy.hcl +++ b/policies/identity_admin_policy.hcl @@ -1,8 +1,13 @@ # Add identity admin role to the token path "identity/*" { - capabilities = ["create", "read", "update", "delete", "list", "sudo"] + capabilities = ["create", "read", "update", "delete", "list"] } -path "identity/entity/*/name" { - capabilities = ["create", "read", "update", "delete", "list", "sudo"] +# Override default policies for identity management +path "identity/entity/id/{{identity.entity.id}}" { + capabilities = ["create", "read", "update", "delete", "list"] +} + +path "identity/entity/name/{{identity.entity.name}}" { + capabilities = ["create", "read", "update", "delete", "list"] }