Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b
29 KiB
counterparty provenance reading index
Historical input only. Current canon and ADR-006 override superseded assertions.
- research/CorpusIndex.md — d110cd1f6653.
- research/README.md — 1ab93b1176ac.
- research/ResearchSeed.md — 1e432ff04d17.
- research/commercial-identity/beneficial-ownership-kyc-boi.md — 602aad062291.
- research/commercial-identity/commercial-identity-nuance-settlement.md — cabb54601ee7.
- research/commercial-identity/commercial-identity-synthesis.md — ac70ecdb2046.
- research/commercial-identity/commercial-trust-binding-theory.md — fc7be6f0641b.
- research/commercial-identity/crm-pipeline-commitment-threshold.md — 459828097e09.
- research/commercial-identity/duns-commercial-credit-identity.md — b33b789b047f.
- research/commercial-identity/eidas-eudi-legal-person-wallet.md — be8b05990cd0.
- research/commercial-identity/kyc-aml-commercial-identity-binding.md — 5d3f63465cd7.
- research/commercial-identity/legal-person-agency-contract.md — c3110cc62b49.
- research/commercial-identity/lei-gleif-legal-entity-identifier.md — ef2ba7156f6d.
- research/commercial-identity/payment-credential-pci-boundary.md — bcacaee7090c.
- research/commercial-identity/registry-identifier-subtypes.md — 1a621787a869.
- research/commercial-identity/reputation-assurance-gradient.md — 0c992d05657d.
- research/commercial-identity/salesforce-crm-commercial-record.md — 52bf8c8dbbd7.
- research/commercial-subscription/b2b-saas-subscriber-tenancy.md — 133bf4325a7c.
- research/commercial-subscription/stripe-customer-billing.md — bb5c8fe3cab7.
- research/identity-provisioning/keycloak-organizations.md — 09c43cdc9ecf.
- research/identity-provisioning/zitadel-organizations-projects.md — f4b1b6f4cce3.
- scenarios/ScenarioTests.md — 400641667064.
- terminology/TerminologyConflictMap.md — 06c8134a399a.
- terminology/TerminologyInventory.md — 5d22816b0bfe.
Shared terminology and scenario fragments
S03. Enterprise With Sub-Organizations
Frozen source: scenarios/ScenarioTests.md lines 36–47; SHA-256 76282210f7df6bf26635ede205ed08215908eb82f8c84d411178bc01516a3f4d.
Historical wording; this is not a current model definition.
## S03. Enterprise With Sub-Organizations
Expected representation: Organization actors linked by structural
relationships, plus Accounts and Membership relationships scoped to relevant
systems.
Checks:
- Sub-organization is not automatically a tenant.
- Legal entity status is modeled separately.
- Membership and administration relationships are explicit.
S04. Vendor Tenant Serving Customer Tenants
Frozen source: scenarios/ScenarioTests.md lines 48–59; SHA-256 f674aa6466c45664d941359e2016a5f43a9ef58f58f1299f1ecb39003ef9a0c3.
Historical wording; this is not a current model definition.
## S04. Vendor Tenant Serving Customer Tenants
Expected representation: Vendor and Customer relationship roles between
Organization actors; Tenant scopes for platform isolation; optional
Administration relationships for delegated support.
Checks:
- Customer is not collapsed into Tenant.
- Vendor is not collapsed into Realm.
- Cross-tenant administration is scoped and evidenced.
S05. Customer Organization With Delegated Administrators
Frozen source: scenarios/ScenarioTests.md lines 60–70; SHA-256 40271bc925011808c60854faf342853ed48ff737afc7885921b62696b02c69d3.
Historical wording; this is not a current model definition.
## S05. Customer Organization With Delegated Administrators
Expected representation: Organization actor, Tenant scope, administrator
Accounts, Delegation and Administration relationships.
Checks:
- Admin rights are relationships, not just group names.
- Delegation has source, target, scope, and lifecycle state.
- Authorization projection can consume the relationship separately.
S07. Spontaneous Interest Group
Frozen source: scenarios/ScenarioTests.md lines 83–93; SHA-256 b4d3ed3df96d57dfc9defcb0395c134e500c79375972ccb978c2abfb64da7247.
Historical wording; this is not a current model definition.
## S07. Spontaneous Interest Group
Expected representation: Community or Group collective actor, Membership
relationships, optional moderator Administration relationships.
Checks:
- Informal group does not need legal entity or tenant semantics.
- Moderation is not the same as membership.
- Group identity can exist without strong real-world identity proofing.
S15. Organization Represented By A Legal Entity And Operational Tenants
Frozen source: scenarios/ScenarioTests.md lines 173–184; SHA-256 a809f4bae8f243f9034887ad2c16903449999ae695c2fc1c4fc089cf9b7020a0.
Historical wording; this is not a current model definition.
## S15. Organization Represented By A Legal Entity And Operational Tenants
Expected representation: Organization actor, Legal Entity specialization or
relationship, one or more Tenant scopes, and Representation relationships for
authorized persons or agents.
Checks:
- Legal entity and tenant are separate model elements.
- Multiple tenants can relate to one organization.
- Representation authority is scoped and evidenced.
Conflict: Account
Frozen source: terminology/TerminologyConflictMap.md lines 44–59; SHA-256 5bc5a473a54d20d4cbba778d5f4508e0655cb755d118583715873b2ca81533a2.
Historical wording; this is not a current model definition.
## Conflict: Account
Problem: account can mean login account, customer billing account, social
media handle, service account, or FOAF online presence.
Source evidence:
- FOAF OnlineAccount is service presence, explicitly not Person (`foaf-agent-person-group-onlineaccount.md`)
- LDAP posixAccount is attribute bundle on person entry (`ldap-rfc4519-inetorgperson-rfc2798.md`)
- ActivityPub `acct:` URI suggests account but actor is richer (`activitypub-actors-followers.md`)
- ZITADEL machine user = Service Account (`zitadel-organizations-projects.md`)
Canonical stance: Account is operational access record in a scope. Billing
records map to Commercial Record; commercial parties use Customer/Vendor roles
and Commercial Relationship.
Conflict: Tenant, Realm, Organization, Customer
Frozen source: terminology/TerminologyConflictMap.md lines 80–99; SHA-256 3e920b787354989a9cce48cc7b45c915150b215b4fcdfe054b854d9cc9748191.
Historical wording; this is not a current model definition.
## Conflict: Tenant, Realm, Organization, Customer
Problem: multi-tenant products collapse isolation boundaries and commercial actors.
Source evidence:
- Keycloak Realm = hard namespace; Organization = B2B overlay (`keycloak-organizations.md`)
- ZITADEL Organization = customer boundary + org actor (`zitadel-organizations-projects.md`)
- SCIM has no tenant; org is string attribute (`scim-rfc7643-rfc7644.md`)
- Schema.org Organization = collective actor (`schema-org-person-organization-membership.md`)
Canonical stance:
- Tenant = administrative/isolation scope
- Realm = issuer/admin namespace (Scope specialization)
- Organization = collective actor
- Customer = commercial relationship role
Model relationships among them; do not synonymize.
Conflict: Synonymity, Linking, Matching, Merge
Frozen source: terminology/TerminologyConflictMap.md lines 163–177; SHA-256 a714d30d2c1bedfcfe3020fa277c5a6226ec408eebd65efc33aadcba9b825ddf.
Historical wording; this is not a current model definition.
## Conflict: Synonymity, Linking, Matching, Merge
Problem: systems collapse probabilistic matches, verified links, and destructive
merges into one feature.
Source evidence:
- Probabilistic matching → weak assertion (`deterministic-vs-probabilistic-matching.md`)
- OIDC iss+sub binding → strong scoped assertion (`oidc`, `synonymity-assertions` notes)
- Schema.org sameAs = weak web equivalence (`schema-org` note)
- GDPR cross-linking raises identifiability risk (`gdpr-pseudonymization.md`)
- MDM golden record merge = downstream anti-pattern (`deterministic` note)
Canonical stance: synonymity is scoped, evidenced, revocable assertion.
Conflict: Customer Account
Frozen source: terminology/TerminologyConflictMap.md lines 204–222; SHA-256 f88abdae039caa5135f7acfb7545747a141fe84703b23f45c918c209d1b73654.
Historical wording; this is not a current model definition.
## Conflict: Customer Account
Problem: `customer account` collapses login account, B2B subscriber organization,
Stripe billing customer, and CRM account into one product noun.
Source evidence:
- Auth0 uses Subscriber for tenant holder, not customer account (`b2b-saas-subscriber-tenancy.md`)
- Stytch: organization is the customer (`b2b-saas-subscriber-tenancy.md`)
- Stripe Customer is billing object with subscriptions, not login (`stripe-customer-billing.md`)
- ZITADEL/Keycloak org-as-tenant has no Customer Account type (`zitadel`, `keycloak` notes)
Canonical stance: **reject Customer Account** as canonical term. Resolve by layer:
- login/access → Account;
- subscribing company → Organization + Customer role + Tenant;
- billing/CRM → Commercial Record;
- vendor↔customer link → Commercial Relationship.
legal entity
Frozen source: terminology/TerminologyInventory.md lines 35–35; SHA-256 da327d376e38707f55e5a1fbcdd4dee8f76bfc6cb4ec2e8468a90079f2ca1a5a.
Historical wording; this is not a current model definition.
| legal entity | Legal Entity | business, compliance | Organization recognized under law; separate from tenant. |
customer
Frozen source: terminology/TerminologyInventory.md lines 36–36; SHA-256 3e7b01c8abe4d58617b4902063eb4f5f14e7cac5da49a8ff778c33f9bc4716a9.
Historical wording; this is not a current model definition.
| customer | Customer (relationship role) | SaaS, vendor models | B2B subscriber org → Organization + Customer role + Tenant. Not Stripe Customer. |
vendor
Frozen source: terminology/TerminologyInventory.md lines 37–37; SHA-256 68a088043e8cb63172b4c57325022708379566e12a9cf605400179c16a4f46b7.
Historical wording; this is not a current model definition.
| vendor | Vendor (relationship role) | SaaS, multi-vendor | Provider role; not realm or tenant. |
subscriber
Frozen source: terminology/TerminologyInventory.md lines 38–38; SHA-256 3194121265ab0f7be752878e2168006b71c72b9f200f1e5e02aac4f078de5bf4.
Historical wording; this is not a current model definition.
| subscriber | Organization + Customer role | Auth0 B2B SaaS | Convenience label only; not canonical. |
stripe customer
Frozen source: terminology/TerminologyInventory.md lines 39–39; SHA-256 925da008d6dd0d1187f038d5bce0a3d6b6d52709672c0c7393f5b538eb65a389.
Historical wording; this is not a current model definition.
| stripe customer | Commercial Record | Stripe, billing | Billing object; link to Tenant via metadata. Not Account. |
payment method / pm_xxx
Frozen source: terminology/TerminologyInventory.md lines 40–40; SHA-256 1877175fcb5e0ce79e8d9145afd4ea37c10cbe9b03a4896568e868a2c38ae9ed.
Historical wording; this is not a current model definition.
| payment method / pm_xxx | Payment Instrument Reference | Stripe, Adyen | Tokenized provider reference; not Credential; not CHD in canon. |
payment mandate / setup intent
Frozen source: terminology/TerminologyInventory.md lines 41–41; SHA-256 aa0254f7ed95210d23dfad3d21c41c7bbe00cc32cf083e496477790f8172872a.
Historical wording; this is not a current model definition.
| payment mandate / setup intent | Payment Mandate (Commercial Commitment) | Stripe, SEPA | Authorization to charge; commitment_type payment_mandate. |
pan / cvv / chd
Frozen source: terminology/TerminologyInventory.md lines 42–42; SHA-256 84eacf96d9ff1a172086a00c1ecf31e94f5b594ee4dce3559e8ccd2525ab6b9c.
Historical wording; this is not a current model definition.
| pan / cvv / chd | Out of canon | PCI DSS | Downstream PCI vault only. |
opportunity (crm)
Frozen source: terminology/TerminologyInventory.md lines 43–43; SHA-256 640774866a49c042fefbd875643f674f087994baea3ae5c6d08566cd20fd05d4.
Historical wording; this is not a current model definition.
| opportunity (crm) | Pipeline Pursuit | Salesforce, HubSpot | In-flight deal; not Commercial Commitment until binding trigger. |
forecast commit (salesforce)
Frozen source: terminology/TerminologyInventory.md lines 44–44; SHA-256 812350a40d1fe20c5018bf1a505190133fa19466a47fc779bd60521551fba7e2.
Historical wording; this is not a current model definition.
| forecast commit (salesforce) | Pipeline Pursuit metadata | Salesforce | Sales forecast category; not Commercial Commitment. |
closed won
Frozen source: terminology/TerminologyInventory.md lines 45–45; SHA-256 945b08bd82ff22f0ac37487ec88482fbe4981779cdf62838cc47f3447a278017.
Historical wording; this is not a current model definition.
| closed won | Pipeline Pursuit lifecycle + optional commitment | CRM | Won stage alone does not auto-create active commitment. |
quote accepted / loi signed
Frozen source: terminology/TerminologyInventory.md lines 46–46; SHA-256 030a9e0caf4d46aab85d60e5941d5ae867e7cec24398c0208e4a9de4888f6edf.
Historical wording; this is not a current model definition.
| quote accepted / loi signed | Commercial Commitment (proposed) | CPQ, sales | Binding trigger with document evidence. |
crm account
Frozen source: terminology/TerminologyInventory.md lines 47–47; SHA-256 fae0815710a180822daf1af506d5fc59210049f8c5e2382e4094326b64a3e47f.
Historical wording; this is not a current model definition.
| crm account | Commercial Record | Salesforce, CRM | Commercial record; not login Account. |
customer account
Frozen source: terminology/TerminologyInventory.md lines 48–48; SHA-256 86c081e76edc36dd60d4c7c2db34ba23506e1e5b1e174459cd68eb65b913cfa2.
Historical wording; this is not a current model definition.
| customer account | Resolve by layer | billing, IAM, CRM | Not canonical — see TerminologyConflictMap. |
commercial record
Frozen source: terminology/TerminologyInventory.md lines 49–49; SHA-256 f509ef49a28b685208eb550efdd95c8dd53ae73ad0d19de697352288fc7bc953.
Historical wording; this is not a current model definition.
| commercial record | Commercial Record | Stripe, CRM, billing | Record layer; payment/subscription/commerce state. |
commercial relationship
Frozen source: terminology/TerminologyInventory.md lines 50–50; SHA-256 295a513939a88bc3fe49df82b43a20b0e89409b1969672a9a627fc63e6265f4c.
Historical wording; this is not a current model definition.
| commercial relationship | Commercial Relationship | vendor/customer SaaS | Vendor-to-customer typed relationship. |
commercial commitment
Frozen source: terminology/TerminologyInventory.md lines 51–51; SHA-256 3363732de312241bd3561fec75ec03893666439f63e5a38f005f729749769b7f.
Historical wording; this is not a current model definition.
| commercial commitment | Commercial Commitment | contracts, subscriptions, KYC | Binding obligation raising identity stakes. |
beneficial owner
Frozen source: terminology/TerminologyInventory.md lines 52–52; SHA-256 5c1d61373f92b79b054fe3d605a5d8171b2af91ebc9b3636f7b07015b3ce85f0.
Historical wording; this is not a current model definition.
| beneficial owner | Beneficial Owner + Beneficial Ownership Relationship | KYC/AML, FinCEN CDD, FATF R24 | Natural person behind legal entity customer; dedicated relationship type with ownership/control prongs. |
beneficial ownership
Frozen source: terminology/TerminologyInventory.md lines 53–53; SHA-256 8520301fabb9a30b9055f47f6b8b957636038fe4f6ec4a34761cfd233780d40a.
Historical wording; this is not a current model definition.
| beneficial ownership | Beneficial Ownership Relationship | FinCEN CDD, BOI, Open Ownership | Regulated Natural Person → Organization/Legal Entity linkage; not Ownership subtype. |
lei
Frozen source: terminology/TerminologyInventory.md lines 54–54; SHA-256 30a480ef227a05028bea2c34eb48bd0e892095df0f69ab496827932e67578b10.
Historical wording; this is not a current model definition.
| lei | Registry Identifier (regulatory_global) | GLEIF, ISO 17442, ICD 0199 | Legal entity identifier with annual renewal. |
duns
Frozen source: terminology/TerminologyInventory.md lines 55–55; SHA-256 e0b1fc126792ef64cf0a52bc555df0d32fee966a8a092cfdc3a93020d4feb7d9.
Historical wording; this is not a current model definition.
| duns | Proxy Commercial Identifier | D&B, ICD 0060 | Commercial-proxy registry identifier. |
uei
Frozen source: terminology/TerminologyInventory.md lines 56–56; SHA-256 20ba5293b13576bc0a7f5a1abde3a3eed2a056d43e34f2451196b9100e8338a3.
Historical wording; this is not a current model definition.
| uei | Registry Identifier (government_registry) | SAM.gov | US federal entity identifier. |
company registration number
Frozen source: terminology/TerminologyInventory.md lines 57–57; SHA-256 837e7698d5f10320661deea52464e849bcfb001472056c75563aded71989c8c4.
Historical wording; this is not a current model definition.
| company registration number | Registry Identifier (government_registry) | national registers, ALEI | Authoritative incorporating-register identifier. |
alei / ibrn
Frozen source: terminology/TerminologyInventory.md lines 58–58; SHA-256 222c1e86c484f60381795e6ba63bbbd684ce1b81eea5d2452ff3ec5a5bdf1dc3.
Historical wording; this is not a current model definition.
| alei / ibrn | Registry Identifier (government_registry) | ISO 8000-116 | Authoritative legal entity identifier from government register. |
iso 6523 / icd
Frozen source: terminology/TerminologyInventory.md lines 59–59; SHA-256 03da1b9755c903ab6c7d865a98c27223f9d7477629602c635394956f3404dc31.
Historical wording; this is not a current model definition.
| iso 6523 / icd | Registry Identifier scheme | ISO/IEC 6523, PEPPOL | ICD + organization identifier encoding. |
legal person
Frozen source: terminology/TerminologyInventory.md lines 60–60; SHA-256 5138cf572034760b21f365bcae5e73346acf6d88c2f65cee751d6b02454d9766.
Historical wording; this is not a current model definition.
| legal person | Legal Person | eIDAS, civil law, agency | Natural or juridical person under law. |
paydex
Frozen source: terminology/TerminologyInventory.md lines 61–61; SHA-256 e33cf7abce1daa982bf86f27307ac02eb6ae0c731c01a2b12f772f79195244f3.
Historical wording; this is not a current model definition.
| paydex | Performance Evidence | D&B | Observed-tier payment performance metric. |
reputation
Frozen source: terminology/TerminologyInventory.md lines 62–62; SHA-256 58cb7704debc05962d158b83e08d874c0c8a90112f1c6306c2977aad9c4a0765.
Historical wording; this is not a current model definition.
| reputation | Resolve by assurance tier | marketplaces, credit | Not canonical — see Counterparty Assurance Gradient. |
star rating / review
Frozen source: terminology/TerminologyInventory.md lines 63–63; SHA-256 3dbb10a8ab536c181da9205e3cfb4fae3031e0fd007fb4bb6205bb532e1959f1.
Historical wording; this is not a current model definition.
| star rating / review | Reputation Signal | Yelp, Amazon, App Store | Opinion-tier Evidence Source; weak, gamable. |
feedback score
Frozen source: terminology/TerminologyInventory.md lines 64–64; SHA-256 331ee6c8952359a690858c0265a784bd3c988f064e14e926c0abc020f5da8043.
Historical wording; this is not a current model definition.
| feedback score | Reputation Signal | eBay, Uber | Platform-local opinion tier. |
credit score
Frozen source: terminology/TerminologyInventory.md lines 65–65; SHA-256 0f724902241a45a7afc6f2fcd1667c19ddfbd32f5cb0d86e5a22031733a3ac70.
Historical wording; this is not a current model definition.
| credit score | Performance Evidence | bureaus, D&B | Observed-tier counterparty metric. |
performance bond / surety
Frozen source: terminology/TerminologyInventory.md lines 66–66; SHA-256 bf0fa441fbe0c7d96001a794d52dba447fd6c38bcd9e91e75fd4fcd70facd1cb.
Historical wording; this is not a current model definition.
| performance bond / surety | Commercial Commitment | construction, procurement | Committed-tier financial assurance. |
escrow
Frozen source: terminology/TerminologyInventory.md lines 67–67; SHA-256 143cdd47e48a1fe59fbf3d5070f82ee380b12332eebf3f2d2588dacdb4aa9752.
Historical wording; this is not a current model definition.
| escrow | Commercial Commitment | marketplaces, Stripe | Committed-tier funds segregation. |
assurance gradient
Frozen source: terminology/TerminologyInventory.md lines 70–70; SHA-256 315b682b202e367b0e9e455b6f686a95a6551ef797affa873cf666d6b1e15daf.
Historical wording; this is not a current model definition.
| assurance gradient | Counterparty Assurance Gradient | commercial identity | Four-tier reliance model (opinion → adjudicated). |
control_basis
Frozen source: terminology/TerminologyInventory.md lines 71–71; SHA-256 7923f00e6a10cdd05fd7b3bc8a5013fc837a36bd1f984fb84fc8f4447e147a7c.
Historical wording; this is not a current model definition.
| control_basis | Beneficial Ownership Relationship metadata | FinCEN CDD, EU AMLD | Settled role enum (chief_executive, managing_member, …). |
binding_trigger
Frozen source: terminology/TerminologyInventory.md lines 72–72; SHA-256 3b5a26c47324d97abaca610e75743903c27ab8ff1d8a69cb5c63d178bfe6ffc5.
Historical wording; this is not a current model definition.
| binding_trigger | Pipeline Pursuit promotion | CRM adapters | Settled enum (quote_accepted, contract_executed, …). |
fincen id
Frozen source: terminology/TerminologyInventory.md lines 73–73; SHA-256 f0bfb45e5363934041ff910a44cd0d69b578679f9c22719365fb0319b314fb78.
Historical wording; this is not a current model definition.
| fincen id | Registry Identifier (government_registry) | BOI | Natural person government registry ID. |
person account
Frozen source: terminology/TerminologyInventory.md lines 74–74; SHA-256 b75fc9b5ca6ef2146e019e342f8565d138eeefccc4b2ee845f010c835d5567eb.
Historical wording; this is not a current model definition.
| person account | Natural Person + Commercial Record | Salesforce B2C | Adapter projection_mode person_account_combined only. |
ncage / cage
Frozen source: terminology/TerminologyInventory.md lines 75–75; SHA-256 cadfb882fc19bda7c60bb8c75e0ed7e2e2b63974037ff07947a8a427d852b9b2.
Historical wording; this is not a current model definition.
| ncage / cage | Registry Identifier (industry_association) | defense procurement | Industry association authority class. |
network token
Frozen source: terminology/TerminologyInventory.md lines 76–76; SHA-256 a5c98ca7a1d5c4561951a88521194c57622622444be59eda1f534a2d4025120c.
Historical wording; this is not a current model definition.
| network token | Payment Instrument Reference | Visa VTS, MDES | instrument_type network_token. |
escrow (platform)
Frozen source: terminology/TerminologyInventory.md lines 77–77; SHA-256 d94b1eae6180f51c462ad52ce0cf8391f303fa035479d3b28d66047cab3dd29d.
Historical wording; this is not a current model definition.
| escrow (platform) | Commercial Commitment (escrow) | marketplaces | Committed tier when funds segregated. |
crm account
Frozen source: terminology/TerminologyInventory.md lines 79–79; SHA-256 9b1dcdfbe61b780895d51b439da2dffc0df0df7cc4dfb4d57de7dd3f8eb30d0e.
Historical wording; this is not a current model definition.
| crm account | Commercial Record | Salesforce | Company/household commercial record. |
bound identity
Frozen source: terminology/TerminologyInventory.md lines 81–81; SHA-256 18eccf5c41c7f60f38e0daa21762e9a88b6a5b829d4166c6b653c970e6f17061.
Historical wording; this is not a current model definition.
| bound identity | Commercial Commitment present | theory | High counterparty reliance; stable identifiers. |
policy
Frozen source: terminology/TerminologyInventory.md lines 117–117; SHA-256 13bcf330fb1989abf5ba4d7c673d2c3a646480236f81792abadb74afa660b983.
Historical wording; this is not a current model definition.
| policy | Authorization Projection | Cedar, Cerbos | Rule artifact; downstream of canon model. |
contextual tuple
Frozen source: terminology/TerminologyInventory.md lines 138–138; SHA-256 5b1c5f8c2795fc54d61f319bd4c6238538588fa4026e779d0ed615e998133218.
Historical wording; this is not a current model definition.
| contextual tuple | Delegation context | OpenFGA | Ephemeral authz fact at check time. |