{"id":"kv-object-scope-rbac-cannot-isolate-teams","text":"Object-scope RBAC in Key Vault cannot fully isolate application teams within a single vault — administrative operations still require vault-level permissions.","truth_value":"IN","source":"entries/2026/03/11/keyvault-rbac.md","source_url":"","source_hash":"4f4dc086f18c4560","justifications":[],"dependents":[],"metadata":{},"explanation":{"steps":[{"node":"kv-object-scope-rbac-cannot-isolate-teams","truth_value":"IN","reason":"premise"}]}}