info-tech-canon/infospace/assimilation/canon-federation/views/itc-ident.md

1440 lines
62 KiB
Markdown
Raw Normal View History

# itc-ident provenance reading index
Historical input only. Current canon and ADR-006 override superseded assertions.
- [research/CorpusIndex.md](../source/research/CorpusIndex.md) — d110cd1f6653.
- [research/README.md](../source/research/README.md) — 1ab93b1176ac.
- [research/ResearchSeed.md](../source/research/ResearchSeed.md) — 1e432ff04d17.
- [research/authentication-federation/nist-800-63-4.md](../source/research/authentication-federation/nist-800-63-4.md) — 8697b739399c.
- [research/authentication-federation/oidc-core-subject-identifiers.md](../source/research/authentication-federation/oidc-core-subject-identifiers.md) — e1a0bf8a2754.
- [research/authentication-federation/saml-nameid-federation.md](../source/research/authentication-federation/saml-nameid-federation.md) — 394457cf75d2.
- [research/authentication-federation/shared-signals-caep-risc.md](../source/research/authentication-federation/shared-signals-caep-risc.md) — 7303fd449a83.
- [research/authorization-relationships/cedar-principal-action-resource-context.md](../source/research/authorization-relationships/cedar-principal-action-resource-context.md) — 1932a8632dd3.
- [research/authorization-relationships/cerbos-abac-derived-roles.md](../source/research/authorization-relationships/cerbos-abac-derived-roles.md) — c35f15042d45.
- [research/authorization-relationships/openfga-modeling.md](../source/research/authorization-relationships/openfga-modeling.md) — e2d03ddfa7be.
- [research/authorization-relationships/zanzibar-rebac.md](../source/research/authorization-relationships/zanzibar-rebac.md) — 1f736195ab4b.
- [research/commercial-identity/beneficial-ownership-kyc-boi.md](../source/research/commercial-identity/beneficial-ownership-kyc-boi.md) — 602aad062291.
- [research/commercial-identity/commercial-identity-nuance-settlement.md](../source/research/commercial-identity/commercial-identity-nuance-settlement.md) — cabb54601ee7.
- [research/commercial-identity/commercial-identity-synthesis.md](../source/research/commercial-identity/commercial-identity-synthesis.md) — ac70ecdb2046.
- [research/commercial-identity/commercial-trust-binding-theory.md](../source/research/commercial-identity/commercial-trust-binding-theory.md) — fc7be6f0641b.
- [research/commercial-identity/crm-pipeline-commitment-threshold.md](../source/research/commercial-identity/crm-pipeline-commitment-threshold.md) — 459828097e09.
- [research/commercial-identity/duns-commercial-credit-identity.md](../source/research/commercial-identity/duns-commercial-credit-identity.md) — b33b789b047f.
- [research/commercial-identity/eidas-eudi-legal-person-wallet.md](../source/research/commercial-identity/eidas-eudi-legal-person-wallet.md) — be8b05990cd0.
- [research/commercial-identity/kyc-aml-commercial-identity-binding.md](../source/research/commercial-identity/kyc-aml-commercial-identity-binding.md) — 5d3f63465cd7.
- [research/commercial-identity/legal-person-agency-contract.md](../source/research/commercial-identity/legal-person-agency-contract.md) — c3110cc62b49.
- [research/commercial-identity/lei-gleif-legal-entity-identifier.md](../source/research/commercial-identity/lei-gleif-legal-entity-identifier.md) — ef2ba7156f6d.
- [research/commercial-identity/payment-credential-pci-boundary.md](../source/research/commercial-identity/payment-credential-pci-boundary.md) — bcacaee7090c.
- [research/commercial-identity/registry-identifier-subtypes.md](../source/research/commercial-identity/registry-identifier-subtypes.md) — 1a621787a869.
- [research/commercial-identity/reputation-assurance-gradient.md](../source/research/commercial-identity/reputation-assurance-gradient.md) — 0c992d05657d.
- [research/commercial-identity/salesforce-crm-commercial-record.md](../source/research/commercial-identity/salesforce-crm-commercial-record.md) — 52bf8c8dbbd7.
- [research/commercial-subscription/b2b-saas-subscriber-tenancy.md](../source/research/commercial-subscription/b2b-saas-subscriber-tenancy.md) — 133bf4325a7c.
- [research/commercial-subscription/stripe-customer-billing.md](../source/research/commercial-subscription/stripe-customer-billing.md) — bb5c8fe3cab7.
- [research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md](../source/research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md) — 12585f844728.
- [research/entity-resolution-privacy/gdpr-pseudonymization.md](../source/research/entity-resolution-privacy/gdpr-pseudonymization.md) — de2bfcf7f52b.
- [research/entity-resolution-privacy/synonymity-assertions.md](../source/research/entity-resolution-privacy/synonymity-assertions.md) — 6ba40ec37221.
- [research/identity-provisioning/keycloak-organizations.md](../source/research/identity-provisioning/keycloak-organizations.md) — 09c43cdc9ecf.
- [research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md](../source/research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md) — c3f3323a3f25.
- [research/identity-provisioning/ory-kratos-keto.md](../source/research/identity-provisioning/ory-kratos-keto.md) — 5cd12c38f8d3.
- [research/identity-provisioning/scim-rfc7643-rfc7644.md](../source/research/identity-provisioning/scim-rfc7643-rfc7644.md) — c5c03952ac2f.
- [research/identity-provisioning/zitadel-organizations-projects.md](../source/research/identity-provisioning/zitadel-organizations-projects.md) — f4b1b6f4cce3.
- [research/social-community-graphs/activitypub-actors-followers.md](../source/research/social-community-graphs/activitypub-actors-followers.md) — 8b28bfc385d1.
- [research/social-community-graphs/foaf-agent-person-group-onlineaccount.md](../source/research/social-community-graphs/foaf-agent-person-group-onlineaccount.md) — 4131e7685da5.
- [research/social-community-graphs/schema-org-person-organization-membership.md](../source/research/social-community-graphs/schema-org-person-organization-membership.md) — bc274f7cf1ff.
- [research/social-community-graphs/webid-solid-profile.md](../source/research/social-community-graphs/webid-solid-profile.md) — abf0c62e23b0.
- [research/verifiable-claims/did-core.md](../source/research/verifiable-claims/did-core.md) — cbe5fd46e093.
- [research/verifiable-claims/openid4vc.md](../source/research/verifiable-claims/openid4vc.md) — e6fcc0612146.
- [research/verifiable-claims/vc-data-model-2.md](../source/research/verifiable-claims/vc-data-model-2.md) — dae7bc679c6c.
- [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) — 400641667064.
- [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) — 06c8134a399a.
- [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) — 5d22816b0bfe.
## Shared terminology and scenario fragments
### S01. Single Person With One Local Account
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 1324; SHA-256 `0040dd866009ad1199e89f89267e3aab86894859f6ae6d07f393e4f0b8cdb6f5`.
Historical wording; this is not a current model definition.
```text
## S01. Single Person With One Local Account
Expected representation: one Natural Person, one Account in an application
Scope, one local Identifier, one Profile, and one Membership or access
relationship if the account belongs to a group.
Checks:
- The person is not identical to the account.
- The profile is not the credential.
- Authorization can project the account or subject into a Principal.
```
### S02. Person With Multiple Accounts Across Scopes
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 2535; SHA-256 `69cabdc1680936fffd25378d9a1fcaa129c258eeca03663a3c9e9718def6fd59`.
Historical wording; this is not a current model definition.
```text
## S02. Person With Multiple Accounts Across Scopes
Expected representation: one Natural Person, multiple Accounts, one Account
per Scope, and optional Synonymity Assertions linking account records.
Checks:
- Each account keeps its source and lifecycle state.
- Linking accounts does not merge them destructively.
- Different scopes can use different identifiers.
```
### S03. Enterprise With Sub-Organizations
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 3647; SHA-256 `76282210f7df6bf26635ede205ed08215908eb82f8c84d411178bc01516a3f4d`.
Historical wording; this is not a current model definition.
```text
## S03. Enterprise With Sub-Organizations
Expected representation: Organization actors linked by structural
relationships, plus Accounts and Membership relationships scoped to relevant
systems.
Checks:
- Sub-organization is not automatically a tenant.
- Legal entity status is modeled separately.
- Membership and administration relationships are explicit.
```
### S04. Vendor Tenant Serving Customer Tenants
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 4859; SHA-256 `f674aa6466c45664d941359e2016a5f43a9ef58f58f1299f1ecb39003ef9a0c3`.
Historical wording; this is not a current model definition.
```text
## S04. Vendor Tenant Serving Customer Tenants
Expected representation: Vendor and Customer relationship roles between
Organization actors; Tenant scopes for platform isolation; optional
Administration relationships for delegated support.
Checks:
- Customer is not collapsed into Tenant.
- Vendor is not collapsed into Realm.
- Cross-tenant administration is scoped and evidenced.
```
### S05. Customer Organization With Delegated Administrators
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 6070; SHA-256 `40271bc925011808c60854faf342853ed48ff737afc7885921b62696b02c69d3`.
Historical wording; this is not a current model definition.
```text
## S05. Customer Organization With Delegated Administrators
Expected representation: Organization actor, Tenant scope, administrator
Accounts, Delegation and Administration relationships.
Checks:
- Admin rights are relationships, not just group names.
- Delegation has source, target, scope, and lifecycle state.
- Authorization projection can consume the relationship separately.
```
### S06. Family With Guardian And Dependent Accounts
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 7182; SHA-256 `a3f0705f7168974632f544891e08403fdcdaa2b205f40ae899bc0483af445106`.
Historical wording; this is not a current model definition.
```text
## S06. Family With Guardian And Dependent Accounts
Expected representation: Family or Household collective actor, Natural Person
actors, guardian/dependent relationships, child Accounts, and privacy
constraints.
Checks:
- Guardian relationship is not generic membership.
- Household and legal family can differ.
- Privacy-sensitive links can be scoped.
```
### S07. Spontaneous Interest Group
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 8393; SHA-256 `b4d3ed3df96d57dfc9defcb0395c134e500c79375972ccb978c2abfb64da7247`.
Historical wording; this is not a current model definition.
```text
## S07. Spontaneous Interest Group
Expected representation: Community or Group collective actor, Membership
relationships, optional moderator Administration relationships.
Checks:
- Informal group does not need legal entity or tenant semantics.
- Moderation is not the same as membership.
- Group identity can exist without strong real-world identity proofing.
```
### S08. Community With Members, Moderators, And Followers
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 94105; SHA-256 `83de4820c3662f015970f7360ceb1278bca3fa8bf63037826316d63643e580ae`.
Historical wording; this is not a current model definition.
```text
## S08. Community With Members, Moderators, And Followers
Expected representation: Community actor; Membership relationships for
members; Administration or moderation relationships for moderators; Following
relationships for followers.
Checks:
- Follower is not a member unless the source says so.
- Moderator authority is explicit and scoped.
- Public profile can differ from account.
```
### S09. Social Media Follower Graph
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 106116; SHA-256 `fd342efc3924c194784c48d937333426addcac7e8404a1834881e284937777b3`.
Historical wording; this is not a current model definition.
```text
## S09. Social Media Follower Graph
Expected representation: Actor or Persona profiles connected by Following
relationships in a social Scope.
Checks:
- Following is directed.
- Following does not imply affiliation, membership, trust, or authorization.
- Pseudonymous profiles can remain scoped.
```
### S10. Bot Or Service Account Acting For An Organization
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 117127; SHA-256 `b7671fae9cd9c0c2070588558e72fc34e6a40a449b088738761253df23955228`.
Historical wording; this is not a current model definition.
```text
## S10. Bot Or Service Account Acting For An Organization
Expected representation: Artificial Agent actor, Service Account, Organization
actor, Representation or Delegation relationship, and Credential records.
Checks:
- Bot is not a natural person.
- Service account has an owner or responsible actor.
- Delegated authority has bounded scope and lifecycle.
```
### S11. AI Agent Acting Under Delegated Authority
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 128139; SHA-256 `c26e3ad239e21e320a65dcee09b95260db582d26ff08c3b7cf537577c9501275`.
Historical wording; this is not a current model definition.
```text
## S11. AI Agent Acting Under Delegated Authority
Expected representation: Artificial Agent actor, Account or Service Account,
Delegation relationship from a Natural Person or Organization, and audit or
evidence references for actions.
Checks:
- Delegation identifies who granted authority.
- Agent actions can be attributed without treating the agent as the person.
- Authorization projection can include delegated context.
```
### S12. Weak Identity Match From Imported Data
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 140150; SHA-256 `b5f26ea04922d59bfe1c7dd240a2348e4afc6cc45a257ea5dfbb733e614649d5`.
Historical wording; this is not a current model definition.
```text
## S12. Weak Identity Match From Imported Data
Expected representation: source Identity Records linked by a weak Synonymity
Assertion with method, evidence, confidence, scope, and lifecycle state.
Checks:
- Weak match does not merge accounts.
- Consumers can reject or quarantine weak links.
- Evidence source remains visible.
```
### S13. Strong Account Link After Explicit Verification
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 151161; SHA-256 `4d4ec21f4e4a70bd1095e0baa7691c39497f970fab42a073683a0200c5ee5949`.
Historical wording; this is not a current model definition.
```text
## S13. Strong Account Link After Explicit Verification
Expected representation: Accounts linked by a strong Synonymity Assertion or
Account Link relationship, with verification evidence and revocation path.
Checks:
- Strong link is still scoped.
- Verification method is recorded.
- Revocation or unlinking is possible.
```
### S14. Pseudonymous Profile Linked Only Within A Restricted Scope
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 162172; SHA-256 `01618fb5fc15400461ceb46402bc5c908fdd3555c3e2aa04adb964faf466bab1`.
Historical wording; this is not a current model definition.
```text
## S14. Pseudonymous Profile Linked Only Within A Restricted Scope
Expected representation: Persona or Profile with Scoped Identifier and
privacy-limited Synonymity Assertion visible only inside an allowed Scope.
Checks:
- Public consumers cannot infer the hidden link.
- The pseudonym can have relationships independent of legal identity.
- Scope boundaries are explicit.
```
### S15. Organization Represented By A Legal Entity And Operational Tenants
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 173184; SHA-256 `a809f4bae8f243f9034887ad2c16903449999ae695c2fc1c4fc089cf9b7020a0`.
Historical wording; this is not a current model definition.
```text
## S15. Organization Represented By A Legal Entity And Operational Tenants
Expected representation: Organization actor, Legal Entity specialization or
relationship, one or more Tenant scopes, and Representation relationships for
authorized persons or agents.
Checks:
- Legal entity and tenant are separate model elements.
- Multiple tenants can relate to one organization.
- Representation authority is scoped and evidenced.
```
### Conflict: User
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 628; SHA-256 `03cc685a840d47b36bf124aa8c1465216dfcb1c463f911dbe5e934b7fa81e3b6`.
Historical wording; this is not a current model definition.
```text
## Conflict: User
Problem: `user` can mean a person, account, login credential holder,
application profile, authorization subject, or product-facing actor.
Source evidence:
- SCIM User = provisionable Identity Record (`scim-rfc7643-rfc7644.md`)
- Keycloak/ZITADEL User = Account with credentials (`keycloak-organizations.md`,
`zitadel-organizations-projects.md`)
- OpenFGA `user:` tuple prefix = Authorization Principal id (`openfga-modeling.md`)
- OIDC End-User = implied Natural Person, not modeled (`oidc-core-subject-identifiers.md`)
Canonical stance: do not use `user` as a root concept.
Current mapping rule:
- Provisioning record (SCIM/LDAP) → Identity Record
- Login-enabled product record → Account
- Public/local display → Profile
- Access evaluation → Principal or Authenticated Subject
- Human being → Natural Person
```
### Conflict: Identity
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 2943; SHA-256 `acf3297ff3ac425a535639c97c8e9368833d0e4e78225679263bcd5ab6ecbbed`.
Historical wording; this is not a current model definition.
```text
## Conflict: Identity
Problem: `identity` can mean selfhood, a directory record, an issuer-bound
subject, a set of claims, a DID, a credential, a profile, or an account.
Source evidence:
- Kratos Identity = traits + credentials (`ory-kratos-keto.md`)
- OIDC developers conflate `sub` with "identity" (`oidc-core-subject-identifiers.md`)
- DID is identifier, not identity record (`did-core.md`)
- VC credentialSubject = claims about subject (`vc-data-model-2.md`)
Canonical stance: avoid bare `identity`. Prefer Identity Record, Identifier,
Claim, Credential, Profile, Persona, or Synonymity Assertion.
```
### Conflict: Account
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 4459; SHA-256 `5bc5a473a54d20d4cbba778d5f4508e0655cb755d118583715873b2ca81533a2`.
Historical wording; this is not a current model definition.
```text
## Conflict: Account
Problem: account can mean login account, customer billing account, social
media handle, service account, or FOAF online presence.
Source evidence:
- FOAF OnlineAccount is service presence, explicitly not Person (`foaf-agent-person-group-onlineaccount.md`)
- LDAP posixAccount is attribute bundle on person entry (`ldap-rfc4519-inetorgperson-rfc2798.md`)
- ActivityPub `acct:` URI suggests account but actor is richer (`activitypub-actors-followers.md`)
- ZITADEL machine user = Service Account (`zitadel-organizations-projects.md`)
Canonical stance: Account is operational access record in a scope. Billing
records map to Commercial Record; commercial parties use Customer/Vendor roles
and Commercial Relationship.
```
### Conflict: Subject, Principal, Actor
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 6079; SHA-256 `5f7282450703c7ab38c6d6b044bf99731c274974dd8ece1785de74bdc1365feb`.
Historical wording; this is not a current model definition.
```text
## Conflict: Subject, Principal, Actor
Problem: protocols, authorization engines, and social models overload these terms.
Source evidence:
- OIDC Subject = issuer-scoped identifier (`oidc-core-subject-identifiers.md`)
- SAML Principal = authenticated subject in assertion (`saml-nameid-federation.md`)
- Cedar Principal = typed entity in authorization request (`cedar-principal-action-resource-context.md`)
- Zanzibar/OpenFGA Subject = opaque authz participant (`zanzibar-rebac.md`)
- ActivityPub Actor = server-hosted social entity (`activitypub-actors-followers.md`)
- FOAF Agent = actionable entity, includes Person (`foaf-agent-person-group-onlineaccount.md`)
- GDPR Data Subject = natural person (`gdpr-pseudonymization.md`)
Canonical stance:
- Actor = conceptual participant
- Authenticated Subject = issuer/protocol view
- Authorization Principal = decision-engine projection
```
### Conflict: Tenant, Realm, Organization, Customer
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 8099; SHA-256 `3e920b787354989a9cce48cc7b45c915150b215b4fcdfe054b854d9cc9748191`.
Historical wording; this is not a current model definition.
```text
## Conflict: Tenant, Realm, Organization, Customer
Problem: multi-tenant products collapse isolation boundaries and commercial actors.
Source evidence:
- Keycloak Realm = hard namespace; Organization = B2B overlay (`keycloak-organizations.md`)
- ZITADEL Organization = customer boundary + org actor (`zitadel-organizations-projects.md`)
- SCIM has no tenant; org is string attribute (`scim-rfc7643-rfc7644.md`)
- Schema.org Organization = collective actor (`schema-org-person-organization-membership.md`)
Canonical stance:
- Tenant = administrative/isolation scope
- Realm = issuer/admin namespace (Scope specialization)
- Organization = collective actor
- Customer = commercial relationship role
Model relationships among them; do not synonymize.
```
### Conflict: Group, Role, Team, Community
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 100119; SHA-256 `0a8cd0ebc16563b59014cbaf3e026ae6633f24aa8f26dabe1c2bfebf70b4f3d4`.
Historical wording; this is not a current model definition.
```text
## Conflict: Group, Role, Team, Community
Problem: IAM groups, collaboration teams, social communities, and authz member
relations use overlapping labels.
Source evidence:
- LDAP/SCIM Group = entry with member references (`ldap`, `scim` notes)
- ActivityPub Group actor = collective social actor (`activitypub-actors-followers.md`)
- Zanzibar `group#member@user` = authz tuple (`zanzibar-rebac.md`)
- Cerbos derived role from group attribute (`cerbos-abac-derived-roles.md`)
- Schema.org Organization subtypes include SportsTeam (`schema-org` note)
Canonical stance:
- Group = named collection with membership
- Role = capability bundle or relationship label
- Team = collaboration group or org unit
- Community = participation-oriented collective actor
```
### Conflict: Member, Follower, Affiliate
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 120133; SHA-256 `59c522c4fa0602246033c3d4bf91b91d718119bc116ad60df9f9c7fda616cefc`.
Historical wording; this is not a current model definition.
```text
## Conflict: Member, Follower, Affiliate
Problem: membership, following, affiliation, and authz member relations hide
distinct semantics behind `member`.
Source evidence:
- ActivityPub Follow ≠ membership (`activitypub-actors-followers.md`)
- Schema.org affiliation looser than memberOf (`schema-org-person-organization-membership.md`)
- OpenFGA organization#member = authz projection (`openfga-modeling.md`)
- FOAF member = group membership; knows = acquaintance (`foaf` note)
Canonical stance: use typed relationships with scope and evidence.
```
### Conflict: Profile And Persona
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 134149; SHA-256 `7e0380ec397e1c991a40391d366913e7087b4a3f45d416b92c068e34a71450b8`.
Historical wording; this is not a current model definition.
```text
## Conflict: Profile And Persona
Problem: profiles are account records, RDF documents, public pages, or VC subjects.
Source evidence:
- WebID profile document = RDF at URI (`webid-solid-profile.md`)
- Kratos traits often called profile informally (`ory-kratos-keto.md`)
- ActivityPub actor profile = public actor representation
- Persona for pairwise/pseudonymous scoped presentation (OIDC, GDPR notes)
Canonical stance:
- Profile = presentation surface in scope
- Persona = deliberate contextual presentation with privacy boundaries
```
### Conflict: Identifier, Credential, Claim
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 150162; SHA-256 `ff9f6502a126229aa65ea20817e698285a74df128aa35ea286cf24f87462216e`.
Historical wording; this is not a current model definition.
```text
## Conflict: Identifier, Credential, Claim
Problem: tokens and documents bundle all three.
Source evidence:
- OIDC ID Token contains sub (identifier) and claims (`oidc-core-subject-identifiers.md`)
- VC = signed claims with proof (`vc-data-model-2.md`)
- DID verification method = cryptographic credential (`did-core.md`)
- SAML AttributeStatement = claims; NameID = identifier (`saml-nameid-federation.md`)
Canonical stance: identifier refers; credential proves; claim states.
```
### Conflict: Synonymity, Linking, Matching, Merge
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 163177; SHA-256 `a714d30d2c1bedfcfe3020fa277c5a6226ec408eebd65efc33aadcba9b825ddf`.
Historical wording; this is not a current model definition.
```text
## Conflict: Synonymity, Linking, Matching, Merge
Problem: systems collapse probabilistic matches, verified links, and destructive
merges into one feature.
Source evidence:
- Probabilistic matching → weak assertion (`deterministic-vs-probabilistic-matching.md`)
- OIDC iss+sub binding → strong scoped assertion (`oidc`, `synonymity-assertions` notes)
- Schema.org sameAs = weak web equivalence (`schema-org` note)
- GDPR cross-linking raises identifiability risk (`gdpr-pseudonymization.md`)
- MDM golden record merge = downstream anti-pattern (`deterministic` note)
Canonical stance: synonymity is scoped, evidenced, revocable assertion.
```
### Conflict: Credential (Auth) vs. Verifiable Credential
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 178190; SHA-256 `ba22d9bb343b383c489c3887a36dafea1c1b93cbed3d9b799727eb5f2a03ecac`.
Historical wording; this is not a current model definition.
```text
## Conflict: Credential (Auth) vs. Verifiable Credential
Problem: "credential" means password, OIDC token, or W3C VC.
Source evidence:
- NIST authenticator/credential (`nist-800-63-4.md`)
- VC Data Model verifiable credential (`vc-data-model-2.md`)
- OpenID4VC bridges OAuth credential terminology with VCs (`openid4vc.md`)
Canonical stance: use Credential with context. VC maps to Credential containing
Claims; login secrets map to Credential (authentication factor).
```
### Conflict: Issuer
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 191203; SHA-256 `e7ca901947a8931fb1c427fa217f22bac361c15aa6c57da67580d799676980a7`.
Historical wording; this is not a current model definition.
```text
## Conflict: Issuer
Problem: issuer means OIDC OP, VC issuer, SAML IdP, or CSP.
Source evidence:
- OIDC iss claim defines subject namespace (`oidc-core-subject-identifiers.md`)
- VC issuer signs credential (`vc-data-model-2.md`)
- NIST CSP performs proofing (`nist-800-63-4.md`)
Canonical stance: Issuer = Scope authority + Trust Relationship; specify protocol
role when mapping.
```
### Conflict: Customer Account
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 204222; SHA-256 `f88abdae039caa5135f7acfb7545747a141fe84703b23f45c918c209d1b73654`.
Historical wording; this is not a current model definition.
```text
## Conflict: Customer Account
Problem: `customer account` collapses login account, B2B subscriber organization,
Stripe billing customer, and CRM account into one product noun.
Source evidence:
- Auth0 uses Subscriber for tenant holder, not customer account (`b2b-saas-subscriber-tenancy.md`)
- Stytch: organization is the customer (`b2b-saas-subscriber-tenancy.md`)
- Stripe Customer is billing object with subscriptions, not login (`stripe-customer-billing.md`)
- ZITADEL/Keycloak org-as-tenant has no Customer Account type (`zitadel`, `keycloak` notes)
Canonical stance: **reject Customer Account** as canonical term. Resolve by layer:
- login/access → Account;
- subscribing company → Organization + Customer role + Tenant;
- billing/CRM → Commercial Record;
- vendor↔customer link → Commercial Relationship.
```
### user
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 1919; SHA-256 `0a171d978928b2781f3b7b7f28485e6d6ec53e8fe7808f42629ea7375101ec3c`.
Historical wording; this is not a current model definition.
```text
| user | Convenience label only | SCIM, LDAP, Keycloak, ZITADEL, apps | Overloaded. Map by context: SCIM/LDAP User → Identity Record; Keycloak/ZITADEL User → Account. |
```
### account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2020; SHA-256 `1901d71fbc43e06b5134161854710bf0f653141bc626bf67d95d4cfd3db0e10f`.
Historical wording; this is not a current model definition.
```text
| account | Account | SCIM, LDAP posixAccount, FOAF OnlineAccount, Keycloak | Operational access record in a scope. FOAF separates account from person explicitly. |
```
### identity
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2121; SHA-256 `779546411717fd6156a3dd3a39eb0869c68d36b10b64fff51e2dc4db9031b422`.
Historical wording; this is not a current model definition.
```text
| identity | Identity Record or Claim | Kratos, OIDC, DID, VC, apps | Kratos Identity = traits + credentials. Avoid bare `identity` as root noun. |
```
### identifier
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2222; SHA-256 `53e9132ea78c16e691b6b0e05371a99aed178d52df6d1e48704b43a40f3193cc`.
Historical wording; this is not a current model definition.
```text
| identifier | Identifier | OIDC sub, SAML NameID, LDAP DN, DID, WebID | Value referring within or across scopes. See Scoped Identifier when correlation is limited. |
```
### scoped identifier
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2323; SHA-256 `e4d333b9c4c275397cbeccd5e0b2eed27b457dff23cca482b42a086885cd2578`.
Historical wording; this is not a current model definition.
```text
| scoped identifier | Scoped Identifier | OIDC pairwise, SAML transient, pseudonyms | Meaning limited to RP, sector, tenant, or session. |
```
### credential
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2424; SHA-256 `c9d2a6c53d2e11f93234cc4fffde742aa82990efc2cb6b83024b929616030248`.
Historical wording; this is not a current model definition.
```text
| credential | Credential | NIST, Kratos, OIDC token, VC, DID keys | Proof material. Distinguish VC (claim container) from password/WebAuthn. |
```
### principal
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2626; SHA-256 `3ab8b5d536f3e1da3f172f95431751a51786291480592b7e2e784338466657ba`.
Historical wording; this is not a current model definition.
```text
| principal | Authorization Principal | Cedar, Cerbos, Zanzibar, OpenFGA | Decision-engine participant. OpenFGA `user:` prefix is not a human user. |
```
### end-user
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2727; SHA-256 `74c3cc32b9d4ce44cf2b61a4673ea73073be69d31900f302937110ab74c43c4c`.
Historical wording; this is not a current model definition.
```text
| end-user | Natural Person (inferred) | OIDC | OIDC names the human implicitly; does not model as entity. |
```
### profile
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2828; SHA-256 `f332b51b59675a5ce79ed19eb9b6ab8d7bbe4e1d651f56099068a1596669db24`.
Historical wording; this is not a current model definition.
```text
| profile | Profile | FOAF, WebID/Solid, SCIM attrs, ActivityPub | Presentation or attribute surface. Solid profile is user-controlled data. |
```
### persona
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2929; SHA-256 `8815441b1d1f825051d8208b5a126c28d1b0a0cec1dc92fc6550b6a79f38eb2d`.
Historical wording; this is not a current model definition.
```text
| persona | Persona | proposal, privacy patterns | Contextual presentation; pairwise/pseudonymous profiles map here. |
```
### bot
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3131; SHA-256 `827962be82a98f1c17ffb62c4f4cd943a66a753d67e5cca0fc8ef77756e8ffad`.
Historical wording; this is not a current model definition.
```text
| bot | Artificial Agent | ActivityPub Service, apps | Automated actor; may use Service Account. |
```
### service account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3232; SHA-256 `64c7a3372e658872cc40799f62c5c3d7d9a8b319340a8134a829ee0a6f6082b0`.
Historical wording; this is not a current model definition.
```text
| service account | Service Account | Keycloak, ZITADEL machine user, Kratos | Non-human login or API identity. ZITADEL machine user, Kratos service patterns. |
```
### machine user
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3333; SHA-256 `5012066796bdd788383852ec7bc34a06a2fa82433dac3afbeca5f625f8b8df13`.
Historical wording; this is not a current model definition.
```text
| machine user | Service Account | ZITADEL | Product term for non-human org identity. |
```
### legal entity
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3535; SHA-256 `da327d376e38707f55e5a1fbcdd4dee8f76bfc6cb4ec2e8468a90079f2ca1a5a`.
Historical wording; this is not a current model definition.
```text
| legal entity | Legal Entity | business, compliance | Organization recognized under law; separate from tenant. |
```
### customer
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3636; SHA-256 `3e7b01c8abe4d58617b4902063eb4f5f14e7cac5da49a8ff778c33f9bc4716a9`.
Historical wording; this is not a current model definition.
```text
| customer | Customer (relationship role) | SaaS, vendor models | B2B subscriber org → Organization + Customer role + Tenant. Not Stripe Customer. |
```
### vendor
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3737; SHA-256 `68a088043e8cb63172b4c57325022708379566e12a9cf605400179c16a4f46b7`.
Historical wording; this is not a current model definition.
```text
| vendor | Vendor (relationship role) | SaaS, multi-vendor | Provider role; not realm or tenant. |
```
### subscriber
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3838; SHA-256 `3194121265ab0f7be752878e2168006b71c72b9f200f1e5e02aac4f078de5bf4`.
Historical wording; this is not a current model definition.
```text
| subscriber | Organization + Customer role | Auth0 B2B SaaS | Convenience label only; not canonical. |
```
### stripe customer
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3939; SHA-256 `925da008d6dd0d1187f038d5bce0a3d6b6d52709672c0c7393f5b538eb65a389`.
Historical wording; this is not a current model definition.
```text
| stripe customer | Commercial Record | Stripe, billing | Billing object; link to Tenant via metadata. Not Account. |
```
### payment method / pm_xxx
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 4040; SHA-256 `1877175fcb5e0ce79e8d9145afd4ea37c10cbe9b03a4896568e868a2c38ae9ed`.
Historical wording; this is not a current model definition.
```text
| payment method / pm_xxx | Payment Instrument Reference | Stripe, Adyen | Tokenized provider reference; not Credential; not CHD in canon. |
```
### pan / cvv / chd
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 4242; SHA-256 `84eacf96d9ff1a172086a00c1ecf31e94f5b594ee4dce3559e8ccd2525ab6b9c`.
Historical wording; this is not a current model definition.
```text
| pan / cvv / chd | Out of canon | PCI DSS | Downstream PCI vault only. |
```
### crm account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 4747; SHA-256 `fae0815710a180822daf1af506d5fc59210049f8c5e2382e4094326b64a3e47f`.
Historical wording; this is not a current model definition.
```text
| crm account | Commercial Record | Salesforce, CRM | Commercial record; not login Account. |
```
### customer account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 4848; SHA-256 `86c081e76edc36dd60d4c7c2db34ba23506e1e5b1e174459cd68eb65b913cfa2`.
Historical wording; this is not a current model definition.
```text
| customer account | Resolve by layer | billing, IAM, CRM | Not canonical — see TerminologyConflictMap. |
```
### commercial relationship
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5050; SHA-256 `295a513939a88bc3fe49df82b43a20b0e89409b1969672a9a627fc63e6265f4c`.
Historical wording; this is not a current model definition.
```text
| commercial relationship | Commercial Relationship | vendor/customer SaaS | Vendor-to-customer typed relationship. |
```
### beneficial owner
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5252; SHA-256 `5c1d61373f92b79b054fe3d605a5d8171b2af91ebc9b3636f7b07015b3ce85f0`.
Historical wording; this is not a current model definition.
```text
| beneficial owner | Beneficial Owner + Beneficial Ownership Relationship | KYC/AML, FinCEN CDD, FATF R24 | Natural person behind legal entity customer; dedicated relationship type with ownership/control prongs. |
```
### beneficial ownership
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5353; SHA-256 `8520301fabb9a30b9055f47f6b8b957636038fe4f6ec4a34761cfd233780d40a`.
Historical wording; this is not a current model definition.
```text
| beneficial ownership | Beneficial Ownership Relationship | FinCEN CDD, BOI, Open Ownership | Regulated Natural Person → Organization/Legal Entity linkage; not Ownership subtype. |
```
### lei
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5454; SHA-256 `30a480ef227a05028bea2c34eb48bd0e892095df0f69ab496827932e67578b10`.
Historical wording; this is not a current model definition.
```text
| lei | Registry Identifier (regulatory_global) | GLEIF, ISO 17442, ICD 0199 | Legal entity identifier with annual renewal. |
```
### duns
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5555; SHA-256 `e0b1fc126792ef64cf0a52bc555df0d32fee966a8a092cfdc3a93020d4feb7d9`.
Historical wording; this is not a current model definition.
```text
| duns | Proxy Commercial Identifier | D&B, ICD 0060 | Commercial-proxy registry identifier. |
```
### uei
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5656; SHA-256 `20ba5293b13576bc0a7f5a1abde3a3eed2a056d43e34f2451196b9100e8338a3`.
Historical wording; this is not a current model definition.
```text
| uei | Registry Identifier (government_registry) | SAM.gov | US federal entity identifier. |
```
### company registration number
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5757; SHA-256 `837e7698d5f10320661deea52464e849bcfb001472056c75563aded71989c8c4`.
Historical wording; this is not a current model definition.
```text
| company registration number | Registry Identifier (government_registry) | national registers, ALEI | Authoritative incorporating-register identifier. |
```
### alei / ibrn
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5858; SHA-256 `222c1e86c484f60381795e6ba63bbbd684ce1b81eea5d2452ff3ec5a5bdf1dc3`.
Historical wording; this is not a current model definition.
```text
| alei / ibrn | Registry Identifier (government_registry) | ISO 8000-116 | Authoritative legal entity identifier from government register. |
```
### iso 6523 / icd
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5959; SHA-256 `03da1b9755c903ab6c7d865a98c27223f9d7477629602c635394956f3404dc31`.
Historical wording; this is not a current model definition.
```text
| iso 6523 / icd | Registry Identifier scheme | ISO/IEC 6523, PEPPOL | ICD + organization identifier encoding. |
```
### control_basis
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7171; SHA-256 `7923f00e6a10cdd05fd7b3bc8a5013fc837a36bd1f984fb84fc8f4447e147a7c`.
Historical wording; this is not a current model definition.
```text
| control_basis | Beneficial Ownership Relationship metadata | FinCEN CDD, EU AMLD | Settled role enum (chief_executive, managing_member, …). |
```
### fincen id
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7373; SHA-256 `f0bfb45e5363934041ff910a44cd0d69b578679f9c22719365fb0319b314fb78`.
Historical wording; this is not a current model definition.
```text
| fincen id | Registry Identifier (government_registry) | BOI | Natural person government registry ID. |
```
### person account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7474; SHA-256 `b75fc9b5ca6ef2146e019e342f8565d138eeefccc4b2ee845f010c835d5567eb`.
Historical wording; this is not a current model definition.
```text
| person account | Natural Person + Commercial Record | Salesforce B2C | Adapter projection_mode person_account_combined only. |
```
### ncage / cage
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7575; SHA-256 `cadfb882fc19bda7c60bb8c75e0ed7e2e2b63974037ff07947a8a427d852b9b2`.
Historical wording; this is not a current model definition.
```text
| ncage / cage | Registry Identifier (industry_association) | defense procurement | Industry association authority class. |
```
### crm account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7979; SHA-256 `9b1dcdfbe61b780895d51b439da2dffc0df0df7cc4dfb4d57de7dd3f8eb30d0e`.
Historical wording; this is not a current model definition.
```text
| crm account | Commercial Record | Salesforce | Company/household commercial record. |
```
### fluid identity
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8080; SHA-256 `3c171e79b1f6966812977a4de526300db7dea729ac4bef4f86737575e836d54e`.
Historical wording; this is not a current model definition.
```text
| fluid identity | Persona / weak binding | theory | Low commercial stake; intentional mutability. |
```
### tenant
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8282; SHA-256 `8ea48ff21a23148aea6923f844adb270f01af86f334bd9fd2e6642e6ac35dc40`.
Historical wording; this is not a current model definition.
```text
| tenant | Tenant | ZITADEL org, SaaS, Keycloak (informal) | Administrative/isolation scope. Keycloak realm sometimes called tenant. |
```
### realm
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8383; SHA-256 `faaa0b5ee2eee0c243c2eda3a90df392858d974bfc1df02422a8df0b71276980`.
Historical wording; this is not a current model definition.
```text
| realm | Realm | Keycloak | Hard identity/admin namespace. Candidate Scope specialization. |
```
### scope
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8484; SHA-256 `05dc1d57cb500d7c30328b063db392cb4e4be19479c2596f739b474e640ec6bb`.
Historical wording; this is not a current model definition.
```text
| scope | Scope | OIDC, Cerbos, OpenFGA store, proposal | Boundary for meaning, policy, or correlation. |
```
### namespace
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8585; SHA-256 `348ff0b2f98a4a7b53947188a958999ec7779c636bb8fcca133075dabe031750`.
Historical wording; this is not a current model definition.
```text
| namespace | Scope | LDAP dc, Keto/OpenFGA, DID method | Naming or authorization partition. |
```
### instance
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8686; SHA-256 `a091b4ac6ab9f52f953832634e1f942fd000ead687ce46a57d4983fd7e79f33d`.
Historical wording; this is not a current model definition.
```text
| instance | Scope | ZITADEL | Deployment-level boundary above organizations. |
```
### project
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8787; SHA-256 `329b17d1d24ed30b039ced9d3e3277cb23e49ea59f4c7ac7acf9ddae3e83dfc7`.
Historical wording; this is not a current model definition.
```text
| project | Application Scope | ZITADEL | Application/product container within org. |
```
### role
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9393; SHA-256 `bf4b3c078725e3a9b4c661c358df673204d21865de9386223c00682de7a76d2a`.
Historical wording; this is not a current model definition.
```text
| role | Role | Keycloak, ZITADEL, Cedar, Cerbos, Schema.org OrganizationRole | Capability bundle or relationship label. Cerbos derived role may hide Ownership. |
```
### grant
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9494; SHA-256 `ca2c9b2882bd176716d5f40b570f7d142e820881529353bdd9829ca2fff5acfd`.
Historical wording; this is not a current model definition.
```text
| grant | Role assignment | ZITADEL | Project role assignment; map to Delegation-like relationship. |
```
### member
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9595; SHA-256 `a6600f7dd9604883a0c366467ad89a90ceee68aefbe6aca09067ada754baae23`.
Historical wording; this is not a current model definition.
```text
| member | Membership Relationship | SCIM, LDAP, FOAF, Schema.org, Zanzibar | Relationship edge, not a noun for the participant. |
```
### affiliation
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9696; SHA-256 `06170379083ad57eb7ec1dee172d3f2e370140f32c1e8b3ccf5a700c3fffdb66`.
Historical wording; this is not a current model definition.
```text
| affiliation | Affiliation Relationship | Schema.org, FOAF knows | Looser than membership. FOAF knows is weak social affiliation. |
```
### follower
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9797; SHA-256 `62256899610e66f10a97b6f7011d52ff02ce79f6d4060c0d403bc8a520f3e6ff`.
Historical wording; this is not a current model definition.
```text
| follower | Following Relationship | ActivityPub | Directed social subscription; not membership or authz. |
```
### follow
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9898; SHA-256 `1c77e34bdf1206d046ef8eee40d4a94393faf67a5af97821834b12b9f9bcea81`.
Historical wording; this is not a current model definition.
```text
| follow | Following Relationship | ActivityPub | Activity establishing follower edge. |
```
### owner
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9999; SHA-256 `78b48373de87a79fc4d67b68b30f7a16c2fbab573b24ddd44f8cfb13487e6896`.
Historical wording; this is not a current model definition.
```text
| owner | Ownership Relationship | Zanzibar, Cerbos derived | Control/responsibility. Cerbos may encode as attribute not relationship. |
```
### administrator
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 100100; SHA-256 `8325a4edc6753be9dadce60ad0fcfd5b46ad0528e0efc0ea9ad3a8d116a93f76`.
Historical wording; this is not a current model definition.
```text
| administrator | Administration Relationship | IAM, ZITADEL grants | Delegated management in scope. |
```
### delegation
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 101101; SHA-256 `538948038bf8b7c7e6c562238017e8efd2c4d2112e542bc9cb7d1d47d521df09`.
Historical wording; this is not a current model definition.
```text
| delegation | Delegation Relationship | Cedar context, agents | Bounded authority grant. Cedar context may carry delegatedBy. |
```
### representation
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 102102; SHA-256 `1a93d64d4e3f608806754d3889b9655d0083e2f5ce92db14780c8513fbfff419`.
Historical wording; this is not a current model definition.
```text
| representation | Representation Relationship | SCIM manager, DID controller | Acting on behalf of another. DID controller may differ from subject. |
```
### trust
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 103103; SHA-256 `3a652a6f5721c7c3616ea4fb93db81e7514538d1f2052eb00cd3333e881dd3c6`.
Historical wording; this is not a current model definition.
```text
| trust | Trust Relationship | federation, VC, DID | Reliance on issuer/verifier; federation metadata trust. |
```
### claim
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 104104; SHA-256 `1ce7bcc854285f598ad1927182e0821d7db9e9fb2a09cbd0d7e743549ca2b37e`.
Historical wording; this is not a current model definition.
```text
| claim | Claim | OIDC, SAML attributes, VC | Statement by issuer. SAML AttributeStatement → Claim. |
```
### assurance
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 106106; SHA-256 `130c61dcb0687328ed992999688e1f37c07958e258a96db49787d1d9fce90dad`.
Historical wording; this is not a current model definition.
```text
| assurance | Assurance Level | NIST IAL/AAL/FAL | Orthogonal identity, authentication, federation confidence. |
```
### identifier binding
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 107107; SHA-256 `384043ffa3353df53a5a4769971853cedccf232fe72d1a8044d1dd3b53cfc378`.
Historical wording; this is not a current model definition.
```text
| identifier binding | Identifier Binding | OIDC iss+sub, WebID-OIDC, SAML | Assertion that identifier refers to target in scope. |
```
### synonymity
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 108108; SHA-256 `58d9d36c18fda3e8df9a74af3c2fae1f3103a6f62df39d0b5db951ce3b6fe5e3`.
Historical wording; this is not a current model definition.
```text
| synonymity | Synonymity Assertion | entity resolution, OIDC linking, schema.org sameAs | Scoped evidenced equivalence. sameAs is weak by default. |
```
### weak match
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 109109; SHA-256 `3f35848a32547aa86fe3ec9e7e755e4fd6392d71ef3d683953df7b08a5c1dd95`.
Historical wording; this is not a current model definition.
```text
| weak match | Weak Synonymity Assertion | probabilistic matching | Probabilistic link; never destructive merge. |
```
### strong link
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 110110; SHA-256 `5f0902c8bed0e10535d0f76427677ac135a5c09b10b223aa49dbe05d8fc6c468`.
Historical wording; this is not a current model definition.
```text
| strong link | Strong Synonymity Assertion | deterministic match, verified linking | Authoritative or verified; still scoped. |
```
### same_as
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 111111; SHA-256 `9236ea638789b858a465b91a73dfb82c2f91434f04d7fe3bb0bcdfa623c6e951`.
Historical wording; this is not a current model definition.
```text
| same_as | Synonymity Assertion (strong) | synonymity model | High-confidence equivalence relation type. |
```
### probably_same_as
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 112112; SHA-256 `1ce7ba621eeb91881b9be16c1e87ce7a78a2a1dd26a0ff7da82b6d3fa04f2069`.
Historical wording; this is not a current model definition.
```text
| probably_same_as | Synonymity Assertion (weak) | probabilistic matching | Probabilistic equivalence relation type. |
```
### linked_to
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 113113; SHA-256 `33b998acec8a52176199992c4d0f5d1ca9016d586682e8fa5d18dbdd27957181`.
Historical wording; this is not a current model definition.
```text
| linked_to | Synonymity Assertion (operational) | account linking | Convenience link without semantic sameness claim. |
```
### pseudonym
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 114114; SHA-256 `01ebfceff32122591e256df20f312f68881ef3e6d4ebfc5738cdfa4cc28d3d69`.
Historical wording; this is not a current model definition.
```text
| pseudonym | Pseudonymous Identifier | GDPR, OIDC pairwise | Limits cross-scope correlation. |
```
### pairwise subject
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 115115; SHA-256 `508a529137ad7a0e7f1409063b306cad3bb1f8aa1c9c15f179c21ab657f46d33`.
Historical wording; this is not a current model definition.
```text
| pairwise subject | Scoped Identifier | OIDC | RP-specific sub preventing global correlation. |
```
### relationship tuple
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 116116; SHA-256 `3cab1bbb2dfc5afd3dcde230e104ddd95e67ccddc46fb2bbcc38f99103a55f49`.
Historical wording; this is not a current model definition.
```text
| relationship tuple | Relationship Tuple | Zanzibar, OpenFGA, Keto | Authz projection: subject#relation@object. |
```
### policy
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 117117; SHA-256 `13bcf330fb1989abf5ba4d7c673d2c3a646480236f81792abadb74afa660b983`.
Historical wording; this is not a current model definition.
```text
| policy | Authorization Projection | Cedar, Cerbos | Rule artifact; downstream of canon model. |
```
### lifecycle state
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 118118; SHA-256 `b39c636369a3c10a22a75c8c686d145f54addfd5720ae90da49321571406d6c6`.
Historical wording; this is not a current model definition.
```text
| lifecycle state | Lifecycle State | SCIM active, SSF/RISC events, VC status | Applies to records, credentials, relationships, assertions. |
```
### subscriber
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 119119; SHA-256 `778a574609c40787ae9fec045e791faafd3d39b49fd187b3c10bc6dad0133e4c`.
Historical wording; this is not a current model definition.
```text
| subscriber | Account / Identity Record | NIST | Enrolled party at CSP; not synonymous with Natural Person until IAL binding. |
```
### issuer
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 120120; SHA-256 `036456fa64e621bcbf2df81938ec5e5bce4af61c757456935846ef3c2c026282`.
Historical wording; this is not a current model definition.
```text
| issuer | Scope + Trust Relationship | OIDC iss, VC issuer, SAML IdP | Namespace authority for identifiers and claims. |
```
### relying party
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 121121; SHA-256 `36a83f3b965a6b2e71938360eb02a5ed64bd665797952d5f592b535e73cfa436`.
Historical wording; this is not a current model definition.
```text
| relying party | Scope | OIDC RP, SAML SP, NIST | Consumer of assertions; RP-local account binding. |
```
### nameid
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 122122; SHA-256 `dbe31e5c4483f1b3f8c83c7abe1239137c7da04456f601d8550035a0c308df12`.
Historical wording; this is not a current model definition.
```text
| nameid | Identifier | SAML | Format attribute determines persistence and privacy semantics. |
```
### distinguished name
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 123123; SHA-256 `ac1bda1aaeb885049b4ae754e1a507b1e872321069f4ca1a3fc3617660d90454`.
Historical wording; this is not a current model definition.
```text
| distinguished name | Identifier | LDAP | Compound locator in directory namespace. |
```
### externalid
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 124124; SHA-256 `e1872cf38aa8e72a824036d017710553cf8ea6f990ef05217c2e972e77c6a978`.
Historical wording; this is not a current model definition.
```text
| externalid | Identifier | SCIM | Client-supplied cross-system correlation key. |
```
### traits
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 125125; SHA-256 `aadb34d5ce8bc3500c5a4d49641d87b11b5da9a481b27dbe0d436d5c0e95117f`.
Historical wording; this is not a current model definition.
```text
| traits | Profile attributes | Kratos | Schema-validated identity attributes. |
```
### verification method
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 126126; SHA-256 `ade6d356c8a8d8db36f1991f72e711738d9281166feda19b6bf5a5ef341d2f10`.
Historical wording; this is not a current model definition.
```text
| verification method | Credential | DID Core | Cryptographic key in DID document. |
```
### verifiable credential
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 127127; SHA-256 `10b80fe4d8c1fd5880c5fb3f626bfff061b2fa2457d93bcaeaa9a6c5d27a69d3`.
Historical wording; this is not a current model definition.
```text
| verifiable credential | Credential + Claim | VC Data Model | Signed claim set; distinct from login credential. |
```
### verifier
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 129129; SHA-256 `d37d10d4b1113114369aa128754a243e56f9ee71e5f95d5d9f966d75fe94088b`.
Historical wording; this is not a current model definition.
```text
| verifier | Scope (evaluation role) | VC, OpenID4VC | Validates presentations. |
```
### did
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 130130; SHA-256 `4de4b5bba75e89eb1ad4dc0525dc0eeb3eb1102e26c3535c0e85c41a68a68551`.
Historical wording; this is not a current model definition.
```text
| did | Identifier | DID Core | Decentralized identifier with method-specific resolution. |
```
### webid
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 131131; SHA-256 `e08c6ed7932919efd4c8f8ae55161be7a02e983d667cf3359fcff0affde44a1b`.
Historical wording; this is not a current model definition.
```text
| webid | Identifier | WebID/Solid | HTTP URI identifying agent with dereferenceable profile. |
```
### pseudonymization
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 133133; SHA-256 `157015a6434ede26ec98e5b223c0d07e1cbf3f9e791ede4c11b8b2958bb67963`.
Historical wording; this is not a current model definition.
```text
| pseudonymization | Processing pattern | GDPR | Technique; maps to Scoped Identifier + separated re-id key. |
```
### tuple (authz)
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 135135; SHA-256 `89a5e53a0468189c92022352aac36ccf34b62a8a34b49c13241eb5fa91aa830c`.
Historical wording; this is not a current model definition.
```text
| tuple (authz) | Relationship Tuple | Zanzibar | Authorization fact, not social relationship. |
```
### derived role
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 137137; SHA-256 `cbfaa9a627d2d32e194e4301e908fd193eb67c788ac3afad98079ce92e898fce`.
Historical wording; this is not a current model definition.
```text
| derived role | Role (computed) | Cerbos | Role from attributes; should trace to Relationship when possible. |
```
### contextual tuple
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 138138; SHA-256 `5b1c5f8c2795fc54d61f319bd4c6238538588fa4026e779d0ed615e998133218`.
Historical wording; this is not a current model definition.
```text
| contextual tuple | Delegation context | OpenFGA | Ephemeral authz fact at check time. |
```
### sameas
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 139139; SHA-256 `be040500605effc4252c681b4b06d22cc0a7f37fbf622b0987690f4f8d39c86a`.
Historical wording; this is not a current model definition.
```text
| sameas | Weak Synonymity Assertion | Schema.org | Informal web equivalence; not strong link without evidence. |
```
### assurance level change
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 141141; SHA-256 `1b1531452b8b67df5a400492a351662c05da740832cc507356df0f1414b40c2b`.
Historical wording; this is not a current model definition.
```text
| assurance level change | Assurance Level update | SSF/CAEP | Event affecting IAL/AAL/FAL metadata. |
```