Scenario
An administrator needs to add a registered user to an application group in AIC to grant the correct access scope for their work. This is commonly required during onboarding, role/team changes, or urgent access enablement. For
Policy-on groups, membership may automatically grant inherited roles, so adding the user to the right group is the approved way to provide access. For
Policy-off groups, membership may provide context but roles might still need to be assigned separately.