<!--
REQUIRED for the biometric Keychain. Proven by elimination: a biometric
SecAccessControl item fails SecItemAdd with errSecMissingEntitlement (-34018)
without a keychain-access-group entitlement, on BOTH the legacy and
data-protection keychains. (Gemini's "default group, no entitlement" claim is
incorrect for biometric items.)
The team-ID prefix (VLK8CVU5H3) makes this a PROFILE-FREE entitlement: a plain
Developer ID signature satisfies it — no provisioning profile required. This
is the only entitlement the CLI needs (no Apple approval, unlike ES/NE).
-->
keychain-access-groups
VLK8CVU5H3.io.quantumencoding.secrets