OptionalderivedOptionalexcludeInternal exclusion prefixes that are never exposed by any profile.
OptionalhiddenHidden/internal profile entries should not be shown in user-facing lists.
OptionalincludePrefixes in FrodoLib object-graph terms, e.g. oauth2oidc or authn.journey.
OptionalpolicyOptional additional policy fields merged into this profile's derived
overlay (alongside the includePathPrefixes-derived allow/deny path
rules) — e.g. self-service's denyTrustTiers, a cross-cutting
restriction that isn't naturally expressed as a subject-area path
prefix.
OptionalpolicyOptional default policy posture for the profile.
True for the derived
allprofile.