browser-oidc-full-restricted with the group (qiwaDevOpsSuper), the client address list (your address/32) and the per-user list switched on. The account passes all three, so the outcome is the geo guard's, which comes last.
| account \ verdict | SA | GB | SA+vpn | none |
|---|---|---|---|---|
| exempt | admitted | admitted | admitted | admitted |
| not-exempt | admitted | QA023 | QA024 | QA022 |
Your address 216.73.216.102: verdict none (no entry: the stand-in answers 404). The account's exemption: off. Switch them on the lab page.
Order: group, client IP, user IP, geo guard: cfg modules/auth_flows/flows.tf:80-84,109-117. Each check passes as in group-member, ip-allowed and user-ip-list; guard as in geo-saudi-only. rep personas.yaml:72-75 (dummy-full-restricted), scenarios.yaml:139-141 (admitted; SA+tor QA024; non-member QA015).