- Roles stored in user attributes, not groups - Property mapping looks up roles by client_id for client_credentials - Service account apps have no policy bindings (client_secret = access control) - Cleanup stale bindings on re-provision - JWT claims: azp (service identity) + roles (capabilities)