A Vault administrator needs to create a policy that grants users read access only to the secrets that belong to their own team. The team membership is stored in an external identity provider and mapped to Vault entity aliases. The administrator wants to use a templated policy that references the entity's metadata. Which policy syntax accomplishes this goal?
The templated path interpolates identity.entity.metadata.team, so each user's entity metadata resolves to their own team's secret path. This grants read and list capabilities only within that team's namespace, satisfying the requirement for per-team access scoped by external identity provider membership.
Why this answer
It uses the proper templating syntax `{{identity.entity.metadata.team}}` to reference the `team` metadata key stored on the Vault entity. This allows the policy to dynamically grant read and list access to the path `secret/data/<team>/*`, ensuring users only see secrets belonging to their own team as defined by the external identity provider.
Exam trap
Vault often tests the distinction between entity metadata and alias metadata, and the trap here is that candidates confuse `{{identity.entity.metadata}}` with `{{identity.entity.aliases}}` or use invalid shorthand like `{{entity.metadata}}` or `{{.team}}`.
How to eliminate wrong answers
Option B is wrong because it uses `{{entity.metadata.team}}` which is not valid ACL policy templating syntax; the correct prefix must be `identity.entity.metadata`. Option C is wrong because `{{.team}}` is a shorthand used in Consul templates, not in Vault ACL policies, and does not reference entity metadata. Option D is wrong because `{{identity.entity.aliases.team}}` incorrectly attempts to access a metadata key directly under aliases; team membership is stored in entity metadata, not in the alias object itself.