What would you use to make Oracle Cloud Infrastructure Identity and Access Management govern resources in a tenancy?
Which volume type contains the image used to boot a compute instance?
Where is sensitive configuration data (like certificates, and credentials) is stored by Kubernetes cluster control plane?

You create a new compartment, "apps," to host some production apps and you create an apps_group and added users to it.
What would you do to ensure the users have access to the apps compartment?