# itc-ident provenance reading index Historical input only. Current canon and ADR-006 override superseded assertions. - [research/CorpusIndex.md](../source/research/CorpusIndex.md) — d110cd1f6653. - [research/README.md](../source/research/README.md) — 1ab93b1176ac. - [research/ResearchSeed.md](../source/research/ResearchSeed.md) — 1e432ff04d17. - [research/authentication-federation/nist-800-63-4.md](../source/research/authentication-federation/nist-800-63-4.md) — 8697b739399c. - [research/authentication-federation/oidc-core-subject-identifiers.md](../source/research/authentication-federation/oidc-core-subject-identifiers.md) — e1a0bf8a2754. - [research/authentication-federation/saml-nameid-federation.md](../source/research/authentication-federation/saml-nameid-federation.md) — 394457cf75d2. - [research/authentication-federation/shared-signals-caep-risc.md](../source/research/authentication-federation/shared-signals-caep-risc.md) — 7303fd449a83. - [research/authorization-relationships/cedar-principal-action-resource-context.md](../source/research/authorization-relationships/cedar-principal-action-resource-context.md) — 1932a8632dd3. - [research/authorization-relationships/cerbos-abac-derived-roles.md](../source/research/authorization-relationships/cerbos-abac-derived-roles.md) — c35f15042d45. - [research/authorization-relationships/openfga-modeling.md](../source/research/authorization-relationships/openfga-modeling.md) — e2d03ddfa7be. - [research/authorization-relationships/zanzibar-rebac.md](../source/research/authorization-relationships/zanzibar-rebac.md) — 1f736195ab4b. - [research/commercial-identity/beneficial-ownership-kyc-boi.md](../source/research/commercial-identity/beneficial-ownership-kyc-boi.md) — 602aad062291. - [research/commercial-identity/commercial-identity-nuance-settlement.md](../source/research/commercial-identity/commercial-identity-nuance-settlement.md) — cabb54601ee7. - [research/commercial-identity/commercial-identity-synthesis.md](../source/research/commercial-identity/commercial-identity-synthesis.md) — ac70ecdb2046. - [research/commercial-identity/commercial-trust-binding-theory.md](../source/research/commercial-identity/commercial-trust-binding-theory.md) — fc7be6f0641b. - [research/commercial-identity/crm-pipeline-commitment-threshold.md](../source/research/commercial-identity/crm-pipeline-commitment-threshold.md) — 459828097e09. - [research/commercial-identity/duns-commercial-credit-identity.md](../source/research/commercial-identity/duns-commercial-credit-identity.md) — b33b789b047f. - [research/commercial-identity/eidas-eudi-legal-person-wallet.md](../source/research/commercial-identity/eidas-eudi-legal-person-wallet.md) — be8b05990cd0. - [research/commercial-identity/kyc-aml-commercial-identity-binding.md](../source/research/commercial-identity/kyc-aml-commercial-identity-binding.md) — 5d3f63465cd7. - [research/commercial-identity/legal-person-agency-contract.md](../source/research/commercial-identity/legal-person-agency-contract.md) — c3110cc62b49. - [research/commercial-identity/lei-gleif-legal-entity-identifier.md](../source/research/commercial-identity/lei-gleif-legal-entity-identifier.md) — ef2ba7156f6d. - [research/commercial-identity/payment-credential-pci-boundary.md](../source/research/commercial-identity/payment-credential-pci-boundary.md) — bcacaee7090c. - [research/commercial-identity/registry-identifier-subtypes.md](../source/research/commercial-identity/registry-identifier-subtypes.md) — 1a621787a869. - [research/commercial-identity/reputation-assurance-gradient.md](../source/research/commercial-identity/reputation-assurance-gradient.md) — 0c992d05657d. - [research/commercial-identity/salesforce-crm-commercial-record.md](../source/research/commercial-identity/salesforce-crm-commercial-record.md) — 52bf8c8dbbd7. - [research/commercial-subscription/b2b-saas-subscriber-tenancy.md](../source/research/commercial-subscription/b2b-saas-subscriber-tenancy.md) — 133bf4325a7c. - [research/commercial-subscription/stripe-customer-billing.md](../source/research/commercial-subscription/stripe-customer-billing.md) — bb5c8fe3cab7. - [research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md](../source/research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md) — 12585f844728. - [research/entity-resolution-privacy/gdpr-pseudonymization.md](../source/research/entity-resolution-privacy/gdpr-pseudonymization.md) — de2bfcf7f52b. - [research/entity-resolution-privacy/synonymity-assertions.md](../source/research/entity-resolution-privacy/synonymity-assertions.md) — 6ba40ec37221. - [research/identity-provisioning/keycloak-organizations.md](../source/research/identity-provisioning/keycloak-organizations.md) — 09c43cdc9ecf. - [research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md](../source/research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md) — c3f3323a3f25. - [research/identity-provisioning/ory-kratos-keto.md](../source/research/identity-provisioning/ory-kratos-keto.md) — 5cd12c38f8d3. - [research/identity-provisioning/scim-rfc7643-rfc7644.md](../source/research/identity-provisioning/scim-rfc7643-rfc7644.md) — c5c03952ac2f. - [research/identity-provisioning/zitadel-organizations-projects.md](../source/research/identity-provisioning/zitadel-organizations-projects.md) — f4b1b6f4cce3. - [research/social-community-graphs/activitypub-actors-followers.md](../source/research/social-community-graphs/activitypub-actors-followers.md) — 8b28bfc385d1. - [research/social-community-graphs/foaf-agent-person-group-onlineaccount.md](../source/research/social-community-graphs/foaf-agent-person-group-onlineaccount.md) — 4131e7685da5. - [research/social-community-graphs/schema-org-person-organization-membership.md](../source/research/social-community-graphs/schema-org-person-organization-membership.md) — bc274f7cf1ff. - [research/social-community-graphs/webid-solid-profile.md](../source/research/social-community-graphs/webid-solid-profile.md) — abf0c62e23b0. - [research/verifiable-claims/did-core.md](../source/research/verifiable-claims/did-core.md) — cbe5fd46e093. - [research/verifiable-claims/openid4vc.md](../source/research/verifiable-claims/openid4vc.md) — e6fcc0612146. - [research/verifiable-claims/vc-data-model-2.md](../source/research/verifiable-claims/vc-data-model-2.md) — dae7bc679c6c. - [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) — 400641667064. - [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) — 06c8134a399a. - [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) — 5d22816b0bfe. ## Shared terminology and scenario fragments ### S01. Single Person With One Local Account Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 13–24; SHA-256 `0040dd866009ad1199e89f89267e3aab86894859f6ae6d07f393e4f0b8cdb6f5`. Historical wording; this is not a current model definition. ```text ## S01. Single Person With One Local Account Expected representation: one Natural Person, one Account in an application Scope, one local Identifier, one Profile, and one Membership or access relationship if the account belongs to a group. Checks: - The person is not identical to the account. - The profile is not the credential. - Authorization can project the account or subject into a Principal. ``` ### S02. Person With Multiple Accounts Across Scopes Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 25–35; SHA-256 `69cabdc1680936fffd25378d9a1fcaa129c258eeca03663a3c9e9718def6fd59`. Historical wording; this is not a current model definition. ```text ## S02. Person With Multiple Accounts Across Scopes Expected representation: one Natural Person, multiple Accounts, one Account per Scope, and optional Synonymity Assertions linking account records. Checks: - Each account keeps its source and lifecycle state. - Linking accounts does not merge them destructively. - Different scopes can use different identifiers. ``` ### S03. Enterprise With Sub-Organizations Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 36–47; SHA-256 `76282210f7df6bf26635ede205ed08215908eb82f8c84d411178bc01516a3f4d`. Historical wording; this is not a current model definition. ```text ## S03. Enterprise With Sub-Organizations Expected representation: Organization actors linked by structural relationships, plus Accounts and Membership relationships scoped to relevant systems. Checks: - Sub-organization is not automatically a tenant. - Legal entity status is modeled separately. - Membership and administration relationships are explicit. ``` ### S04. Vendor Tenant Serving Customer Tenants Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 48–59; SHA-256 `f674aa6466c45664d941359e2016a5f43a9ef58f58f1299f1ecb39003ef9a0c3`. Historical wording; this is not a current model definition. ```text ## S04. Vendor Tenant Serving Customer Tenants Expected representation: Vendor and Customer relationship roles between Organization actors; Tenant scopes for platform isolation; optional Administration relationships for delegated support. Checks: - Customer is not collapsed into Tenant. - Vendor is not collapsed into Realm. - Cross-tenant administration is scoped and evidenced. ``` ### S05. Customer Organization With Delegated Administrators Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 60–70; SHA-256 `40271bc925011808c60854faf342853ed48ff737afc7885921b62696b02c69d3`. Historical wording; this is not a current model definition. ```text ## S05. Customer Organization With Delegated Administrators Expected representation: Organization actor, Tenant scope, administrator Accounts, Delegation and Administration relationships. Checks: - Admin rights are relationships, not just group names. - Delegation has source, target, scope, and lifecycle state. - Authorization projection can consume the relationship separately. ``` ### S06. Family With Guardian And Dependent Accounts Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 71–82; SHA-256 `a3f0705f7168974632f544891e08403fdcdaa2b205f40ae899bc0483af445106`. Historical wording; this is not a current model definition. ```text ## S06. Family With Guardian And Dependent Accounts Expected representation: Family or Household collective actor, Natural Person actors, guardian/dependent relationships, child Accounts, and privacy constraints. Checks: - Guardian relationship is not generic membership. - Household and legal family can differ. - Privacy-sensitive links can be scoped. ``` ### S07. Spontaneous Interest Group Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 83–93; SHA-256 `b4d3ed3df96d57dfc9defcb0395c134e500c79375972ccb978c2abfb64da7247`. Historical wording; this is not a current model definition. ```text ## S07. Spontaneous Interest Group Expected representation: Community or Group collective actor, Membership relationships, optional moderator Administration relationships. Checks: - Informal group does not need legal entity or tenant semantics. - Moderation is not the same as membership. - Group identity can exist without strong real-world identity proofing. ``` ### S08. Community With Members, Moderators, And Followers Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 94–105; SHA-256 `83de4820c3662f015970f7360ceb1278bca3fa8bf63037826316d63643e580ae`. Historical wording; this is not a current model definition. ```text ## S08. Community With Members, Moderators, And Followers Expected representation: Community actor; Membership relationships for members; Administration or moderation relationships for moderators; Following relationships for followers. Checks: - Follower is not a member unless the source says so. - Moderator authority is explicit and scoped. - Public profile can differ from account. ``` ### S09. Social Media Follower Graph Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 106–116; SHA-256 `fd342efc3924c194784c48d937333426addcac7e8404a1834881e284937777b3`. Historical wording; this is not a current model definition. ```text ## S09. Social Media Follower Graph Expected representation: Actor or Persona profiles connected by Following relationships in a social Scope. Checks: - Following is directed. - Following does not imply affiliation, membership, trust, or authorization. - Pseudonymous profiles can remain scoped. ``` ### S10. Bot Or Service Account Acting For An Organization Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 117–127; SHA-256 `b7671fae9cd9c0c2070588558e72fc34e6a40a449b088738761253df23955228`. Historical wording; this is not a current model definition. ```text ## S10. Bot Or Service Account Acting For An Organization Expected representation: Artificial Agent actor, Service Account, Organization actor, Representation or Delegation relationship, and Credential records. Checks: - Bot is not a natural person. - Service account has an owner or responsible actor. - Delegated authority has bounded scope and lifecycle. ``` ### S11. AI Agent Acting Under Delegated Authority Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 128–139; SHA-256 `c26e3ad239e21e320a65dcee09b95260db582d26ff08c3b7cf537577c9501275`. Historical wording; this is not a current model definition. ```text ## S11. AI Agent Acting Under Delegated Authority Expected representation: Artificial Agent actor, Account or Service Account, Delegation relationship from a Natural Person or Organization, and audit or evidence references for actions. Checks: - Delegation identifies who granted authority. - Agent actions can be attributed without treating the agent as the person. - Authorization projection can include delegated context. ``` ### S12. Weak Identity Match From Imported Data Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 140–150; SHA-256 `b5f26ea04922d59bfe1c7dd240a2348e4afc6cc45a257ea5dfbb733e614649d5`. Historical wording; this is not a current model definition. ```text ## S12. Weak Identity Match From Imported Data Expected representation: source Identity Records linked by a weak Synonymity Assertion with method, evidence, confidence, scope, and lifecycle state. Checks: - Weak match does not merge accounts. - Consumers can reject or quarantine weak links. - Evidence source remains visible. ``` ### S13. Strong Account Link After Explicit Verification Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 151–161; SHA-256 `4d4ec21f4e4a70bd1095e0baa7691c39497f970fab42a073683a0200c5ee5949`. Historical wording; this is not a current model definition. ```text ## S13. Strong Account Link After Explicit Verification Expected representation: Accounts linked by a strong Synonymity Assertion or Account Link relationship, with verification evidence and revocation path. Checks: - Strong link is still scoped. - Verification method is recorded. - Revocation or unlinking is possible. ``` ### S14. Pseudonymous Profile Linked Only Within A Restricted Scope Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 162–172; SHA-256 `01618fb5fc15400461ceb46402bc5c908fdd3555c3e2aa04adb964faf466bab1`. Historical wording; this is not a current model definition. ```text ## S14. Pseudonymous Profile Linked Only Within A Restricted Scope Expected representation: Persona or Profile with Scoped Identifier and privacy-limited Synonymity Assertion visible only inside an allowed Scope. Checks: - Public consumers cannot infer the hidden link. - The pseudonym can have relationships independent of legal identity. - Scope boundaries are explicit. ``` ### S15. Organization Represented By A Legal Entity And Operational Tenants Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 173–184; SHA-256 `a809f4bae8f243f9034887ad2c16903449999ae695c2fc1c4fc089cf9b7020a0`. Historical wording; this is not a current model definition. ```text ## S15. Organization Represented By A Legal Entity And Operational Tenants Expected representation: Organization actor, Legal Entity specialization or relationship, one or more Tenant scopes, and Representation relationships for authorized persons or agents. Checks: - Legal entity and tenant are separate model elements. - Multiple tenants can relate to one organization. - Representation authority is scoped and evidenced. ``` ### Conflict: User Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 6–28; SHA-256 `03cc685a840d47b36bf124aa8c1465216dfcb1c463f911dbe5e934b7fa81e3b6`. Historical wording; this is not a current model definition. ```text ## Conflict: User Problem: `user` can mean a person, account, login credential holder, application profile, authorization subject, or product-facing actor. Source evidence: - SCIM User = provisionable Identity Record (`scim-rfc7643-rfc7644.md`) - Keycloak/ZITADEL User = Account with credentials (`keycloak-organizations.md`, `zitadel-organizations-projects.md`) - OpenFGA `user:` tuple prefix = Authorization Principal id (`openfga-modeling.md`) - OIDC End-User = implied Natural Person, not modeled (`oidc-core-subject-identifiers.md`) Canonical stance: do not use `user` as a root concept. Current mapping rule: - Provisioning record (SCIM/LDAP) → Identity Record - Login-enabled product record → Account - Public/local display → Profile - Access evaluation → Principal or Authenticated Subject - Human being → Natural Person ``` ### Conflict: Identity Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 29–43; SHA-256 `acf3297ff3ac425a535639c97c8e9368833d0e4e78225679263bcd5ab6ecbbed`. Historical wording; this is not a current model definition. ```text ## Conflict: Identity Problem: `identity` can mean selfhood, a directory record, an issuer-bound subject, a set of claims, a DID, a credential, a profile, or an account. Source evidence: - Kratos Identity = traits + credentials (`ory-kratos-keto.md`) - OIDC developers conflate `sub` with "identity" (`oidc-core-subject-identifiers.md`) - DID is identifier, not identity record (`did-core.md`) - VC credentialSubject = claims about subject (`vc-data-model-2.md`) Canonical stance: avoid bare `identity`. Prefer Identity Record, Identifier, Claim, Credential, Profile, Persona, or Synonymity Assertion. ``` ### Conflict: Account Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 44–59; SHA-256 `5bc5a473a54d20d4cbba778d5f4508e0655cb755d118583715873b2ca81533a2`. Historical wording; this is not a current model definition. ```text ## Conflict: Account Problem: account can mean login account, customer billing account, social media handle, service account, or FOAF online presence. Source evidence: - FOAF OnlineAccount is service presence, explicitly not Person (`foaf-agent-person-group-onlineaccount.md`) - LDAP posixAccount is attribute bundle on person entry (`ldap-rfc4519-inetorgperson-rfc2798.md`) - ActivityPub `acct:` URI suggests account but actor is richer (`activitypub-actors-followers.md`) - ZITADEL machine user = Service Account (`zitadel-organizations-projects.md`) Canonical stance: Account is operational access record in a scope. Billing records map to Commercial Record; commercial parties use Customer/Vendor roles and Commercial Relationship. ``` ### Conflict: Subject, Principal, Actor Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 60–79; SHA-256 `5f7282450703c7ab38c6d6b044bf99731c274974dd8ece1785de74bdc1365feb`. Historical wording; this is not a current model definition. ```text ## Conflict: Subject, Principal, Actor Problem: protocols, authorization engines, and social models overload these terms. Source evidence: - OIDC Subject = issuer-scoped identifier (`oidc-core-subject-identifiers.md`) - SAML Principal = authenticated subject in assertion (`saml-nameid-federation.md`) - Cedar Principal = typed entity in authorization request (`cedar-principal-action-resource-context.md`) - Zanzibar/OpenFGA Subject = opaque authz participant (`zanzibar-rebac.md`) - ActivityPub Actor = server-hosted social entity (`activitypub-actors-followers.md`) - FOAF Agent = actionable entity, includes Person (`foaf-agent-person-group-onlineaccount.md`) - GDPR Data Subject = natural person (`gdpr-pseudonymization.md`) Canonical stance: - Actor = conceptual participant - Authenticated Subject = issuer/protocol view - Authorization Principal = decision-engine projection ``` ### Conflict: Tenant, Realm, Organization, Customer Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 80–99; SHA-256 `3e920b787354989a9cce48cc7b45c915150b215b4fcdfe054b854d9cc9748191`. Historical wording; this is not a current model definition. ```text ## Conflict: Tenant, Realm, Organization, Customer Problem: multi-tenant products collapse isolation boundaries and commercial actors. Source evidence: - Keycloak Realm = hard namespace; Organization = B2B overlay (`keycloak-organizations.md`) - ZITADEL Organization = customer boundary + org actor (`zitadel-organizations-projects.md`) - SCIM has no tenant; org is string attribute (`scim-rfc7643-rfc7644.md`) - Schema.org Organization = collective actor (`schema-org-person-organization-membership.md`) Canonical stance: - Tenant = administrative/isolation scope - Realm = issuer/admin namespace (Scope specialization) - Organization = collective actor - Customer = commercial relationship role Model relationships among them; do not synonymize. ``` ### Conflict: Group, Role, Team, Community Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 100–119; SHA-256 `0a8cd0ebc16563b59014cbaf3e026ae6633f24aa8f26dabe1c2bfebf70b4f3d4`. Historical wording; this is not a current model definition. ```text ## Conflict: Group, Role, Team, Community Problem: IAM groups, collaboration teams, social communities, and authz member relations use overlapping labels. Source evidence: - LDAP/SCIM Group = entry with member references (`ldap`, `scim` notes) - ActivityPub Group actor = collective social actor (`activitypub-actors-followers.md`) - Zanzibar `group#member@user` = authz tuple (`zanzibar-rebac.md`) - Cerbos derived role from group attribute (`cerbos-abac-derived-roles.md`) - Schema.org Organization subtypes include SportsTeam (`schema-org` note) Canonical stance: - Group = named collection with membership - Role = capability bundle or relationship label - Team = collaboration group or org unit - Community = participation-oriented collective actor ``` ### Conflict: Member, Follower, Affiliate Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 120–133; SHA-256 `59c522c4fa0602246033c3d4bf91b91d718119bc116ad60df9f9c7fda616cefc`. Historical wording; this is not a current model definition. ```text ## Conflict: Member, Follower, Affiliate Problem: membership, following, affiliation, and authz member relations hide distinct semantics behind `member`. Source evidence: - ActivityPub Follow ≠ membership (`activitypub-actors-followers.md`) - Schema.org affiliation looser than memberOf (`schema-org-person-organization-membership.md`) - OpenFGA organization#member = authz projection (`openfga-modeling.md`) - FOAF member = group membership; knows = acquaintance (`foaf` note) Canonical stance: use typed relationships with scope and evidence. ``` ### Conflict: Profile And Persona Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 134–149; SHA-256 `7e0380ec397e1c991a40391d366913e7087b4a3f45d416b92c068e34a71450b8`. Historical wording; this is not a current model definition. ```text ## Conflict: Profile And Persona Problem: profiles are account records, RDF documents, public pages, or VC subjects. Source evidence: - WebID profile document = RDF at URI (`webid-solid-profile.md`) - Kratos traits often called profile informally (`ory-kratos-keto.md`) - ActivityPub actor profile = public actor representation - Persona for pairwise/pseudonymous scoped presentation (OIDC, GDPR notes) Canonical stance: - Profile = presentation surface in scope - Persona = deliberate contextual presentation with privacy boundaries ``` ### Conflict: Identifier, Credential, Claim Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 150–162; SHA-256 `ff9f6502a126229aa65ea20817e698285a74df128aa35ea286cf24f87462216e`. Historical wording; this is not a current model definition. ```text ## Conflict: Identifier, Credential, Claim Problem: tokens and documents bundle all three. Source evidence: - OIDC ID Token contains sub (identifier) and claims (`oidc-core-subject-identifiers.md`) - VC = signed claims with proof (`vc-data-model-2.md`) - DID verification method = cryptographic credential (`did-core.md`) - SAML AttributeStatement = claims; NameID = identifier (`saml-nameid-federation.md`) Canonical stance: identifier refers; credential proves; claim states. ``` ### Conflict: Synonymity, Linking, Matching, Merge Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 163–177; SHA-256 `a714d30d2c1bedfcfe3020fa277c5a6226ec408eebd65efc33aadcba9b825ddf`. Historical wording; this is not a current model definition. ```text ## Conflict: Synonymity, Linking, Matching, Merge Problem: systems collapse probabilistic matches, verified links, and destructive merges into one feature. Source evidence: - Probabilistic matching → weak assertion (`deterministic-vs-probabilistic-matching.md`) - OIDC iss+sub binding → strong scoped assertion (`oidc`, `synonymity-assertions` notes) - Schema.org sameAs = weak web equivalence (`schema-org` note) - GDPR cross-linking raises identifiability risk (`gdpr-pseudonymization.md`) - MDM golden record merge = downstream anti-pattern (`deterministic` note) Canonical stance: synonymity is scoped, evidenced, revocable assertion. ``` ### Conflict: Credential (Auth) vs. Verifiable Credential Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 178–190; SHA-256 `ba22d9bb343b383c489c3887a36dafea1c1b93cbed3d9b799727eb5f2a03ecac`. Historical wording; this is not a current model definition. ```text ## Conflict: Credential (Auth) vs. Verifiable Credential Problem: "credential" means password, OIDC token, or W3C VC. Source evidence: - NIST authenticator/credential (`nist-800-63-4.md`) - VC Data Model verifiable credential (`vc-data-model-2.md`) - OpenID4VC bridges OAuth credential terminology with VCs (`openid4vc.md`) Canonical stance: use Credential with context. VC maps to Credential containing Claims; login secrets map to Credential (authentication factor). ``` ### Conflict: Issuer Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 191–203; SHA-256 `e7ca901947a8931fb1c427fa217f22bac361c15aa6c57da67580d799676980a7`. Historical wording; this is not a current model definition. ```text ## Conflict: Issuer Problem: issuer means OIDC OP, VC issuer, SAML IdP, or CSP. Source evidence: - OIDC iss claim defines subject namespace (`oidc-core-subject-identifiers.md`) - VC issuer signs credential (`vc-data-model-2.md`) - NIST CSP performs proofing (`nist-800-63-4.md`) Canonical stance: Issuer = Scope authority + Trust Relationship; specify protocol role when mapping. ``` ### Conflict: Customer Account Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 204–222; SHA-256 `f88abdae039caa5135f7acfb7545747a141fe84703b23f45c918c209d1b73654`. Historical wording; this is not a current model definition. ```text ## Conflict: Customer Account Problem: `customer account` collapses login account, B2B subscriber organization, Stripe billing customer, and CRM account into one product noun. Source evidence: - Auth0 uses Subscriber for tenant holder, not customer account (`b2b-saas-subscriber-tenancy.md`) - Stytch: organization is the customer (`b2b-saas-subscriber-tenancy.md`) - Stripe Customer is billing object with subscriptions, not login (`stripe-customer-billing.md`) - ZITADEL/Keycloak org-as-tenant has no Customer Account type (`zitadel`, `keycloak` notes) Canonical stance: **reject Customer Account** as canonical term. Resolve by layer: - login/access → Account; - subscribing company → Organization + Customer role + Tenant; - billing/CRM → Commercial Record; - vendor↔customer link → Commercial Relationship. ``` ### user Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 19–19; SHA-256 `0a171d978928b2781f3b7b7f28485e6d6ec53e8fe7808f42629ea7375101ec3c`. Historical wording; this is not a current model definition. ```text | user | Convenience label only | SCIM, LDAP, Keycloak, ZITADEL, apps | Overloaded. Map by context: SCIM/LDAP User → Identity Record; Keycloak/ZITADEL User → Account. | ``` ### account Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 20–20; SHA-256 `1901d71fbc43e06b5134161854710bf0f653141bc626bf67d95d4cfd3db0e10f`. Historical wording; this is not a current model definition. ```text | account | Account | SCIM, LDAP posixAccount, FOAF OnlineAccount, Keycloak | Operational access record in a scope. FOAF separates account from person explicitly. | ``` ### identity Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 21–21; SHA-256 `779546411717fd6156a3dd3a39eb0869c68d36b10b64fff51e2dc4db9031b422`. Historical wording; this is not a current model definition. ```text | identity | Identity Record or Claim | Kratos, OIDC, DID, VC, apps | Kratos Identity = traits + credentials. Avoid bare `identity` as root noun. | ``` ### identifier Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 22–22; SHA-256 `53e9132ea78c16e691b6b0e05371a99aed178d52df6d1e48704b43a40f3193cc`. Historical wording; this is not a current model definition. ```text | identifier | Identifier | OIDC sub, SAML NameID, LDAP DN, DID, WebID | Value referring within or across scopes. See Scoped Identifier when correlation is limited. | ``` ### scoped identifier Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 23–23; SHA-256 `e4d333b9c4c275397cbeccd5e0b2eed27b457dff23cca482b42a086885cd2578`. Historical wording; this is not a current model definition. ```text | scoped identifier | Scoped Identifier | OIDC pairwise, SAML transient, pseudonyms | Meaning limited to RP, sector, tenant, or session. | ``` ### credential Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 24–24; SHA-256 `c9d2a6c53d2e11f93234cc4fffde742aa82990efc2cb6b83024b929616030248`. Historical wording; this is not a current model definition. ```text | credential | Credential | NIST, Kratos, OIDC token, VC, DID keys | Proof material. Distinguish VC (claim container) from password/WebAuthn. | ``` ### principal Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 26–26; SHA-256 `3ab8b5d536f3e1da3f172f95431751a51786291480592b7e2e784338466657ba`. Historical wording; this is not a current model definition. ```text | principal | Authorization Principal | Cedar, Cerbos, Zanzibar, OpenFGA | Decision-engine participant. OpenFGA `user:` prefix is not a human user. | ``` ### end-user Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 27–27; SHA-256 `74c3cc32b9d4ce44cf2b61a4673ea73073be69d31900f302937110ab74c43c4c`. Historical wording; this is not a current model definition. ```text | end-user | Natural Person (inferred) | OIDC | OIDC names the human implicitly; does not model as entity. | ``` ### profile Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 28–28; SHA-256 `f332b51b59675a5ce79ed19eb9b6ab8d7bbe4e1d651f56099068a1596669db24`. Historical wording; this is not a current model definition. ```text | profile | Profile | FOAF, WebID/Solid, SCIM attrs, ActivityPub | Presentation or attribute surface. Solid profile is user-controlled data. | ``` ### persona Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 29–29; SHA-256 `8815441b1d1f825051d8208b5a126c28d1b0a0cec1dc92fc6550b6a79f38eb2d`. Historical wording; this is not a current model definition. ```text | persona | Persona | proposal, privacy patterns | Contextual presentation; pairwise/pseudonymous profiles map here. | ``` ### bot Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 31–31; SHA-256 `827962be82a98f1c17ffb62c4f4cd943a66a753d67e5cca0fc8ef77756e8ffad`. Historical wording; this is not a current model definition. ```text | bot | Artificial Agent | ActivityPub Service, apps | Automated actor; may use Service Account. | ``` ### service account Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 32–32; SHA-256 `64c7a3372e658872cc40799f62c5c3d7d9a8b319340a8134a829ee0a6f6082b0`. Historical wording; this is not a current model definition. ```text | service account | Service Account | Keycloak, ZITADEL machine user, Kratos | Non-human login or API identity. ZITADEL machine user, Kratos service patterns. | ``` ### machine user Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 33–33; SHA-256 `5012066796bdd788383852ec7bc34a06a2fa82433dac3afbeca5f625f8b8df13`. Historical wording; this is not a current model definition. ```text | machine user | Service Account | ZITADEL | Product term for non-human org identity. | ``` ### legal entity Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 35–35; SHA-256 `da327d376e38707f55e5a1fbcdd4dee8f76bfc6cb4ec2e8468a90079f2ca1a5a`. Historical wording; this is not a current model definition. ```text | legal entity | Legal Entity | business, compliance | Organization recognized under law; separate from tenant. | ``` ### customer Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 36–36; SHA-256 `3e7b01c8abe4d58617b4902063eb4f5f14e7cac5da49a8ff778c33f9bc4716a9`. Historical wording; this is not a current model definition. ```text | customer | Customer (relationship role) | SaaS, vendor models | B2B subscriber org → Organization + Customer role + Tenant. Not Stripe Customer. | ``` ### vendor Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 37–37; SHA-256 `68a088043e8cb63172b4c57325022708379566e12a9cf605400179c16a4f46b7`. Historical wording; this is not a current model definition. ```text | vendor | Vendor (relationship role) | SaaS, multi-vendor | Provider role; not realm or tenant. | ``` ### subscriber Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 38–38; SHA-256 `3194121265ab0f7be752878e2168006b71c72b9f200f1e5e02aac4f078de5bf4`. Historical wording; this is not a current model definition. ```text | subscriber | Organization + Customer role | Auth0 B2B SaaS | Convenience label only; not canonical. | ``` ### stripe customer Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 39–39; SHA-256 `925da008d6dd0d1187f038d5bce0a3d6b6d52709672c0c7393f5b538eb65a389`. Historical wording; this is not a current model definition. ```text | stripe customer | Commercial Record | Stripe, billing | Billing object; link to Tenant via metadata. Not Account. | ``` ### payment method / pm_xxx Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 40–40; SHA-256 `1877175fcb5e0ce79e8d9145afd4ea37c10cbe9b03a4896568e868a2c38ae9ed`. Historical wording; this is not a current model definition. ```text | payment method / pm_xxx | Payment Instrument Reference | Stripe, Adyen | Tokenized provider reference; not Credential; not CHD in canon. | ``` ### pan / cvv / chd Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 42–42; SHA-256 `84eacf96d9ff1a172086a00c1ecf31e94f5b594ee4dce3559e8ccd2525ab6b9c`. Historical wording; this is not a current model definition. ```text | pan / cvv / chd | Out of canon | PCI DSS | Downstream PCI vault only. | ``` ### crm account Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 47–47; SHA-256 `fae0815710a180822daf1af506d5fc59210049f8c5e2382e4094326b64a3e47f`. Historical wording; this is not a current model definition. ```text | crm account | Commercial Record | Salesforce, CRM | Commercial record; not login Account. | ``` ### customer account Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 48–48; SHA-256 `86c081e76edc36dd60d4c7c2db34ba23506e1e5b1e174459cd68eb65b913cfa2`. Historical wording; this is not a current model definition. ```text | customer account | Resolve by layer | billing, IAM, CRM | Not canonical — see TerminologyConflictMap. | ``` ### commercial relationship Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 50–50; SHA-256 `295a513939a88bc3fe49df82b43a20b0e89409b1969672a9a627fc63e6265f4c`. Historical wording; this is not a current model definition. ```text | commercial relationship | Commercial Relationship | vendor/customer SaaS | Vendor-to-customer typed relationship. | ``` ### beneficial owner Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 52–52; SHA-256 `5c1d61373f92b79b054fe3d605a5d8171b2af91ebc9b3636f7b07015b3ce85f0`. Historical wording; this is not a current model definition. ```text | beneficial owner | Beneficial Owner + Beneficial Ownership Relationship | KYC/AML, FinCEN CDD, FATF R24 | Natural person behind legal entity customer; dedicated relationship type with ownership/control prongs. | ``` ### beneficial ownership Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 53–53; SHA-256 `8520301fabb9a30b9055f47f6b8b957636038fe4f6ec4a34761cfd233780d40a`. Historical wording; this is not a current model definition. ```text | beneficial ownership | Beneficial Ownership Relationship | FinCEN CDD, BOI, Open Ownership | Regulated Natural Person → Organization/Legal Entity linkage; not Ownership subtype. | ``` ### lei Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 54–54; SHA-256 `30a480ef227a05028bea2c34eb48bd0e892095df0f69ab496827932e67578b10`. Historical wording; this is not a current model definition. ```text | lei | Registry Identifier (regulatory_global) | GLEIF, ISO 17442, ICD 0199 | Legal entity identifier with annual renewal. | ``` ### duns Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 55–55; SHA-256 `e0b1fc126792ef64cf0a52bc555df0d32fee966a8a092cfdc3a93020d4feb7d9`. Historical wording; this is not a current model definition. ```text | duns | Proxy Commercial Identifier | D&B, ICD 0060 | Commercial-proxy registry identifier. | ``` ### uei Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 56–56; SHA-256 `20ba5293b13576bc0a7f5a1abde3a3eed2a056d43e34f2451196b9100e8338a3`. Historical wording; this is not a current model definition. ```text | uei | Registry Identifier (government_registry) | SAM.gov | US federal entity identifier. | ``` ### company registration number Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 57–57; SHA-256 `837e7698d5f10320661deea52464e849bcfb001472056c75563aded71989c8c4`. Historical wording; this is not a current model definition. ```text | company registration number | Registry Identifier (government_registry) | national registers, ALEI | Authoritative incorporating-register identifier. | ``` ### alei / ibrn Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 58–58; SHA-256 `222c1e86c484f60381795e6ba63bbbd684ce1b81eea5d2452ff3ec5a5bdf1dc3`. Historical wording; this is not a current model definition. ```text | alei / ibrn | Registry Identifier (government_registry) | ISO 8000-116 | Authoritative legal entity identifier from government register. | ``` ### iso 6523 / icd Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 59–59; SHA-256 `03da1b9755c903ab6c7d865a98c27223f9d7477629602c635394956f3404dc31`. Historical wording; this is not a current model definition. ```text | iso 6523 / icd | Registry Identifier scheme | ISO/IEC 6523, PEPPOL | ICD + organization identifier encoding. | ``` ### control_basis Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 71–71; SHA-256 `7923f00e6a10cdd05fd7b3bc8a5013fc837a36bd1f984fb84fc8f4447e147a7c`. Historical wording; this is not a current model definition. ```text | control_basis | Beneficial Ownership Relationship metadata | FinCEN CDD, EU AMLD | Settled role enum (chief_executive, managing_member, …). | ``` ### fincen id Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 73–73; SHA-256 `f0bfb45e5363934041ff910a44cd0d69b578679f9c22719365fb0319b314fb78`. Historical wording; this is not a current model definition. ```text | fincen id | Registry Identifier (government_registry) | BOI | Natural person government registry ID. | ``` ### person account Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 74–74; SHA-256 `b75fc9b5ca6ef2146e019e342f8565d138eeefccc4b2ee845f010c835d5567eb`. Historical wording; this is not a current model definition. ```text | person account | Natural Person + Commercial Record | Salesforce B2C | Adapter projection_mode person_account_combined only. | ``` ### ncage / cage Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 75–75; SHA-256 `cadfb882fc19bda7c60bb8c75e0ed7e2e2b63974037ff07947a8a427d852b9b2`. Historical wording; this is not a current model definition. ```text | ncage / cage | Registry Identifier (industry_association) | defense procurement | Industry association authority class. | ``` ### crm account Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 79–79; SHA-256 `9b1dcdfbe61b780895d51b439da2dffc0df0df7cc4dfb4d57de7dd3f8eb30d0e`. Historical wording; this is not a current model definition. ```text | crm account | Commercial Record | Salesforce | Company/household commercial record. | ``` ### fluid identity Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 80–80; SHA-256 `3c171e79b1f6966812977a4de526300db7dea729ac4bef4f86737575e836d54e`. Historical wording; this is not a current model definition. ```text | fluid identity | Persona / weak binding | theory | Low commercial stake; intentional mutability. | ``` ### tenant Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 82–82; SHA-256 `8ea48ff21a23148aea6923f844adb270f01af86f334bd9fd2e6642e6ac35dc40`. Historical wording; this is not a current model definition. ```text | tenant | Tenant | ZITADEL org, SaaS, Keycloak (informal) | Administrative/isolation scope. Keycloak realm sometimes called tenant. | ``` ### realm Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 83–83; SHA-256 `faaa0b5ee2eee0c243c2eda3a90df392858d974bfc1df02422a8df0b71276980`. Historical wording; this is not a current model definition. ```text | realm | Realm | Keycloak | Hard identity/admin namespace. Candidate Scope specialization. | ``` ### scope Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 84–84; SHA-256 `05dc1d57cb500d7c30328b063db392cb4e4be19479c2596f739b474e640ec6bb`. Historical wording; this is not a current model definition. ```text | scope | Scope | OIDC, Cerbos, OpenFGA store, proposal | Boundary for meaning, policy, or correlation. | ``` ### namespace Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 85–85; SHA-256 `348ff0b2f98a4a7b53947188a958999ec7779c636bb8fcca133075dabe031750`. Historical wording; this is not a current model definition. ```text | namespace | Scope | LDAP dc, Keto/OpenFGA, DID method | Naming or authorization partition. | ``` ### instance Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 86–86; SHA-256 `a091b4ac6ab9f52f953832634e1f942fd000ead687ce46a57d4983fd7e79f33d`. Historical wording; this is not a current model definition. ```text | instance | Scope | ZITADEL | Deployment-level boundary above organizations. | ``` ### project Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 87–87; SHA-256 `329b17d1d24ed30b039ced9d3e3277cb23e49ea59f4c7ac7acf9ddae3e83dfc7`. Historical wording; this is not a current model definition. ```text | project | Application Scope | ZITADEL | Application/product container within org. | ``` ### role Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 93–93; SHA-256 `bf4b3c078725e3a9b4c661c358df673204d21865de9386223c00682de7a76d2a`. Historical wording; this is not a current model definition. ```text | role | Role | Keycloak, ZITADEL, Cedar, Cerbos, Schema.org OrganizationRole | Capability bundle or relationship label. Cerbos derived role may hide Ownership. | ``` ### grant Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 94–94; SHA-256 `ca2c9b2882bd176716d5f40b570f7d142e820881529353bdd9829ca2fff5acfd`. Historical wording; this is not a current model definition. ```text | grant | Role assignment | ZITADEL | Project role assignment; map to Delegation-like relationship. | ``` ### member Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 95–95; SHA-256 `a6600f7dd9604883a0c366467ad89a90ceee68aefbe6aca09067ada754baae23`. Historical wording; this is not a current model definition. ```text | member | Membership Relationship | SCIM, LDAP, FOAF, Schema.org, Zanzibar | Relationship edge, not a noun for the participant. | ``` ### affiliation Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 96–96; SHA-256 `06170379083ad57eb7ec1dee172d3f2e370140f32c1e8b3ccf5a700c3fffdb66`. Historical wording; this is not a current model definition. ```text | affiliation | Affiliation Relationship | Schema.org, FOAF knows | Looser than membership. FOAF knows is weak social affiliation. | ``` ### follower Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 97–97; SHA-256 `62256899610e66f10a97b6f7011d52ff02ce79f6d4060c0d403bc8a520f3e6ff`. Historical wording; this is not a current model definition. ```text | follower | Following Relationship | ActivityPub | Directed social subscription; not membership or authz. | ``` ### follow Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 98–98; SHA-256 `1c77e34bdf1206d046ef8eee40d4a94393faf67a5af97821834b12b9f9bcea81`. Historical wording; this is not a current model definition. ```text | follow | Following Relationship | ActivityPub | Activity establishing follower edge. | ``` ### owner Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 99–99; SHA-256 `78b48373de87a79fc4d67b68b30f7a16c2fbab573b24ddd44f8cfb13487e6896`. Historical wording; this is not a current model definition. ```text | owner | Ownership Relationship | Zanzibar, Cerbos derived | Control/responsibility. Cerbos may encode as attribute not relationship. | ``` ### administrator Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 100–100; SHA-256 `8325a4edc6753be9dadce60ad0fcfd5b46ad0528e0efc0ea9ad3a8d116a93f76`. Historical wording; this is not a current model definition. ```text | administrator | Administration Relationship | IAM, ZITADEL grants | Delegated management in scope. | ``` ### delegation Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 101–101; SHA-256 `538948038bf8b7c7e6c562238017e8efd2c4d2112e542bc9cb7d1d47d521df09`. Historical wording; this is not a current model definition. ```text | delegation | Delegation Relationship | Cedar context, agents | Bounded authority grant. Cedar context may carry delegatedBy. | ``` ### representation Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 102–102; SHA-256 `1a93d64d4e3f608806754d3889b9655d0083e2f5ce92db14780c8513fbfff419`. Historical wording; this is not a current model definition. ```text | representation | Representation Relationship | SCIM manager, DID controller | Acting on behalf of another. DID controller may differ from subject. | ``` ### trust Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 103–103; SHA-256 `3a652a6f5721c7c3616ea4fb93db81e7514538d1f2052eb00cd3333e881dd3c6`. Historical wording; this is not a current model definition. ```text | trust | Trust Relationship | federation, VC, DID | Reliance on issuer/verifier; federation metadata trust. | ``` ### claim Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 104–104; SHA-256 `1ce7bcc854285f598ad1927182e0821d7db9e9fb2a09cbd0d7e743549ca2b37e`. Historical wording; this is not a current model definition. ```text | claim | Claim | OIDC, SAML attributes, VC | Statement by issuer. SAML AttributeStatement → Claim. | ``` ### assurance Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 106–106; SHA-256 `130c61dcb0687328ed992999688e1f37c07958e258a96db49787d1d9fce90dad`. Historical wording; this is not a current model definition. ```text | assurance | Assurance Level | NIST IAL/AAL/FAL | Orthogonal identity, authentication, federation confidence. | ``` ### identifier binding Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 107–107; SHA-256 `384043ffa3353df53a5a4769971853cedccf232fe72d1a8044d1dd3b53cfc378`. Historical wording; this is not a current model definition. ```text | identifier binding | Identifier Binding | OIDC iss+sub, WebID-OIDC, SAML | Assertion that identifier refers to target in scope. | ``` ### synonymity Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 108–108; SHA-256 `58d9d36c18fda3e8df9a74af3c2fae1f3103a6f62df39d0b5db951ce3b6fe5e3`. Historical wording; this is not a current model definition. ```text | synonymity | Synonymity Assertion | entity resolution, OIDC linking, schema.org sameAs | Scoped evidenced equivalence. sameAs is weak by default. | ``` ### weak match Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 109–109; SHA-256 `3f35848a32547aa86fe3ec9e7e755e4fd6392d71ef3d683953df7b08a5c1dd95`. Historical wording; this is not a current model definition. ```text | weak match | Weak Synonymity Assertion | probabilistic matching | Probabilistic link; never destructive merge. | ``` ### strong link Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 110–110; SHA-256 `5f0902c8bed0e10535d0f76427677ac135a5c09b10b223aa49dbe05d8fc6c468`. Historical wording; this is not a current model definition. ```text | strong link | Strong Synonymity Assertion | deterministic match, verified linking | Authoritative or verified; still scoped. | ``` ### same_as Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 111–111; SHA-256 `9236ea638789b858a465b91a73dfb82c2f91434f04d7fe3bb0bcdfa623c6e951`. Historical wording; this is not a current model definition. ```text | same_as | Synonymity Assertion (strong) | synonymity model | High-confidence equivalence relation type. | ``` ### probably_same_as Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 112–112; SHA-256 `1ce7ba621eeb91881b9be16c1e87ce7a78a2a1dd26a0ff7da82b6d3fa04f2069`. Historical wording; this is not a current model definition. ```text | probably_same_as | Synonymity Assertion (weak) | probabilistic matching | Probabilistic equivalence relation type. | ``` ### linked_to Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 113–113; SHA-256 `33b998acec8a52176199992c4d0f5d1ca9016d586682e8fa5d18dbdd27957181`. Historical wording; this is not a current model definition. ```text | linked_to | Synonymity Assertion (operational) | account linking | Convenience link without semantic sameness claim. | ``` ### pseudonym Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 114–114; SHA-256 `01ebfceff32122591e256df20f312f68881ef3e6d4ebfc5738cdfa4cc28d3d69`. Historical wording; this is not a current model definition. ```text | pseudonym | Pseudonymous Identifier | GDPR, OIDC pairwise | Limits cross-scope correlation. | ``` ### pairwise subject Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 115–115; SHA-256 `508a529137ad7a0e7f1409063b306cad3bb1f8aa1c9c15f179c21ab657f46d33`. Historical wording; this is not a current model definition. ```text | pairwise subject | Scoped Identifier | OIDC | RP-specific sub preventing global correlation. | ``` ### relationship tuple Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 116–116; SHA-256 `3cab1bbb2dfc5afd3dcde230e104ddd95e67ccddc46fb2bbcc38f99103a55f49`. Historical wording; this is not a current model definition. ```text | relationship tuple | Relationship Tuple | Zanzibar, OpenFGA, Keto | Authz projection: subject#relation@object. | ``` ### policy Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 117–117; SHA-256 `13bcf330fb1989abf5ba4d7c673d2c3a646480236f81792abadb74afa660b983`. Historical wording; this is not a current model definition. ```text | policy | Authorization Projection | Cedar, Cerbos | Rule artifact; downstream of canon model. | ``` ### lifecycle state Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 118–118; SHA-256 `b39c636369a3c10a22a75c8c686d145f54addfd5720ae90da49321571406d6c6`. Historical wording; this is not a current model definition. ```text | lifecycle state | Lifecycle State | SCIM active, SSF/RISC events, VC status | Applies to records, credentials, relationships, assertions. | ``` ### subscriber Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 119–119; SHA-256 `778a574609c40787ae9fec045e791faafd3d39b49fd187b3c10bc6dad0133e4c`. Historical wording; this is not a current model definition. ```text | subscriber | Account / Identity Record | NIST | Enrolled party at CSP; not synonymous with Natural Person until IAL binding. | ``` ### issuer Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 120–120; SHA-256 `036456fa64e621bcbf2df81938ec5e5bce4af61c757456935846ef3c2c026282`. Historical wording; this is not a current model definition. ```text | issuer | Scope + Trust Relationship | OIDC iss, VC issuer, SAML IdP | Namespace authority for identifiers and claims. | ``` ### relying party Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 121–121; SHA-256 `36a83f3b965a6b2e71938360eb02a5ed64bd665797952d5f592b535e73cfa436`. Historical wording; this is not a current model definition. ```text | relying party | Scope | OIDC RP, SAML SP, NIST | Consumer of assertions; RP-local account binding. | ``` ### nameid Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 122–122; SHA-256 `dbe31e5c4483f1b3f8c83c7abe1239137c7da04456f601d8550035a0c308df12`. Historical wording; this is not a current model definition. ```text | nameid | Identifier | SAML | Format attribute determines persistence and privacy semantics. | ``` ### distinguished name Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 123–123; SHA-256 `ac1bda1aaeb885049b4ae754e1a507b1e872321069f4ca1a3fc3617660d90454`. Historical wording; this is not a current model definition. ```text | distinguished name | Identifier | LDAP | Compound locator in directory namespace. | ``` ### externalid Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 124–124; SHA-256 `e1872cf38aa8e72a824036d017710553cf8ea6f990ef05217c2e972e77c6a978`. Historical wording; this is not a current model definition. ```text | externalid | Identifier | SCIM | Client-supplied cross-system correlation key. | ``` ### traits Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 125–125; SHA-256 `aadb34d5ce8bc3500c5a4d49641d87b11b5da9a481b27dbe0d436d5c0e95117f`. Historical wording; this is not a current model definition. ```text | traits | Profile attributes | Kratos | Schema-validated identity attributes. | ``` ### verification method Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 126–126; SHA-256 `ade6d356c8a8d8db36f1991f72e711738d9281166feda19b6bf5a5ef341d2f10`. Historical wording; this is not a current model definition. ```text | verification method | Credential | DID Core | Cryptographic key in DID document. | ``` ### verifiable credential Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 127–127; SHA-256 `10b80fe4d8c1fd5880c5fb3f626bfff061b2fa2457d93bcaeaa9a6c5d27a69d3`. Historical wording; this is not a current model definition. ```text | verifiable credential | Credential + Claim | VC Data Model | Signed claim set; distinct from login credential. | ``` ### verifier Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 129–129; SHA-256 `d37d10d4b1113114369aa128754a243e56f9ee71e5f95d5d9f966d75fe94088b`. Historical wording; this is not a current model definition. ```text | verifier | Scope (evaluation role) | VC, OpenID4VC | Validates presentations. | ``` ### did Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 130–130; SHA-256 `4de4b5bba75e89eb1ad4dc0525dc0eeb3eb1102e26c3535c0e85c41a68a68551`. Historical wording; this is not a current model definition. ```text | did | Identifier | DID Core | Decentralized identifier with method-specific resolution. | ``` ### webid Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 131–131; SHA-256 `e08c6ed7932919efd4c8f8ae55161be7a02e983d667cf3359fcff0affde44a1b`. Historical wording; this is not a current model definition. ```text | webid | Identifier | WebID/Solid | HTTP URI identifying agent with dereferenceable profile. | ``` ### pseudonymization Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 133–133; SHA-256 `157015a6434ede26ec98e5b223c0d07e1cbf3f9e791ede4c11b8b2958bb67963`. Historical wording; this is not a current model definition. ```text | pseudonymization | Processing pattern | GDPR | Technique; maps to Scoped Identifier + separated re-id key. | ``` ### tuple (authz) Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 135–135; SHA-256 `89a5e53a0468189c92022352aac36ccf34b62a8a34b49c13241eb5fa91aa830c`. Historical wording; this is not a current model definition. ```text | tuple (authz) | Relationship Tuple | Zanzibar | Authorization fact, not social relationship. | ``` ### derived role Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 137–137; SHA-256 `cbfaa9a627d2d32e194e4301e908fd193eb67c788ac3afad98079ce92e898fce`. Historical wording; this is not a current model definition. ```text | derived role | Role (computed) | Cerbos | Role from attributes; should trace to Relationship when possible. | ``` ### contextual tuple Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 138–138; SHA-256 `5b1c5f8c2795fc54d61f319bd4c6238538588fa4026e779d0ed615e998133218`. Historical wording; this is not a current model definition. ```text | contextual tuple | Delegation context | OpenFGA | Ephemeral authz fact at check time. | ``` ### sameas Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 139–139; SHA-256 `be040500605effc4252c681b4b06d22cc0a7f37fbf622b0987690f4f8d39c86a`. Historical wording; this is not a current model definition. ```text | sameas | Weak Synonymity Assertion | Schema.org | Informal web equivalence; not strong link without evidence. | ``` ### assurance level change Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 141–141; SHA-256 `1b1531452b8b67df5a400492a351662c05da740832cc507356df0f1414b40c2b`. Historical wording; this is not a current model definition. ```text | assurance level change | Assurance Level update | SSF/CAEP | Event affecting IAL/AAL/FAL metadata. | ```