Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b
62 KiB
itc-ident provenance reading index
Historical input only. Current canon and ADR-006 override superseded assertions.
- research/CorpusIndex.md — d110cd1f6653.
- research/README.md — 1ab93b1176ac.
- research/ResearchSeed.md — 1e432ff04d17.
- research/authentication-federation/nist-800-63-4.md — 8697b739399c.
- research/authentication-federation/oidc-core-subject-identifiers.md — e1a0bf8a2754.
- research/authentication-federation/saml-nameid-federation.md — 394457cf75d2.
- research/authentication-federation/shared-signals-caep-risc.md — 7303fd449a83.
- research/authorization-relationships/cedar-principal-action-resource-context.md — 1932a8632dd3.
- research/authorization-relationships/cerbos-abac-derived-roles.md — c35f15042d45.
- research/authorization-relationships/openfga-modeling.md — e2d03ddfa7be.
- research/authorization-relationships/zanzibar-rebac.md — 1f736195ab4b.
- research/commercial-identity/beneficial-ownership-kyc-boi.md — 602aad062291.
- research/commercial-identity/commercial-identity-nuance-settlement.md — cabb54601ee7.
- research/commercial-identity/commercial-identity-synthesis.md — ac70ecdb2046.
- research/commercial-identity/commercial-trust-binding-theory.md — fc7be6f0641b.
- research/commercial-identity/crm-pipeline-commitment-threshold.md — 459828097e09.
- research/commercial-identity/duns-commercial-credit-identity.md — b33b789b047f.
- research/commercial-identity/eidas-eudi-legal-person-wallet.md — be8b05990cd0.
- research/commercial-identity/kyc-aml-commercial-identity-binding.md — 5d3f63465cd7.
- research/commercial-identity/legal-person-agency-contract.md — c3110cc62b49.
- research/commercial-identity/lei-gleif-legal-entity-identifier.md — ef2ba7156f6d.
- research/commercial-identity/payment-credential-pci-boundary.md — bcacaee7090c.
- research/commercial-identity/registry-identifier-subtypes.md — 1a621787a869.
- research/commercial-identity/reputation-assurance-gradient.md — 0c992d05657d.
- research/commercial-identity/salesforce-crm-commercial-record.md — 52bf8c8dbbd7.
- research/commercial-subscription/b2b-saas-subscriber-tenancy.md — 133bf4325a7c.
- research/commercial-subscription/stripe-customer-billing.md — bb5c8fe3cab7.
- research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md — 12585f844728.
- research/entity-resolution-privacy/gdpr-pseudonymization.md — de2bfcf7f52b.
- research/entity-resolution-privacy/synonymity-assertions.md — 6ba40ec37221.
- research/identity-provisioning/keycloak-organizations.md — 09c43cdc9ecf.
- research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md — c3f3323a3f25.
- research/identity-provisioning/ory-kratos-keto.md — 5cd12c38f8d3.
- research/identity-provisioning/scim-rfc7643-rfc7644.md — c5c03952ac2f.
- research/identity-provisioning/zitadel-organizations-projects.md — f4b1b6f4cce3.
- research/social-community-graphs/activitypub-actors-followers.md — 8b28bfc385d1.
- research/social-community-graphs/foaf-agent-person-group-onlineaccount.md — 4131e7685da5.
- research/social-community-graphs/schema-org-person-organization-membership.md — bc274f7cf1ff.
- research/social-community-graphs/webid-solid-profile.md — abf0c62e23b0.
- research/verifiable-claims/did-core.md — cbe5fd46e093.
- research/verifiable-claims/openid4vc.md — e6fcc0612146.
- research/verifiable-claims/vc-data-model-2.md — dae7bc679c6c.
- scenarios/ScenarioTests.md — 400641667064.
- terminology/TerminologyConflictMap.md — 06c8134a399a.
- terminology/TerminologyInventory.md — 5d22816b0bfe.
Shared terminology and scenario fragments
S01. Single Person With One Local Account
Frozen source: scenarios/ScenarioTests.md lines 13–24; SHA-256 0040dd866009ad1199e89f89267e3aab86894859f6ae6d07f393e4f0b8cdb6f5.
Historical wording; this is not a current model definition.
## S01. Single Person With One Local Account
Expected representation: one Natural Person, one Account in an application
Scope, one local Identifier, one Profile, and one Membership or access
relationship if the account belongs to a group.
Checks:
- The person is not identical to the account.
- The profile is not the credential.
- Authorization can project the account or subject into a Principal.
S02. Person With Multiple Accounts Across Scopes
Frozen source: scenarios/ScenarioTests.md lines 25–35; SHA-256 69cabdc1680936fffd25378d9a1fcaa129c258eeca03663a3c9e9718def6fd59.
Historical wording; this is not a current model definition.
## S02. Person With Multiple Accounts Across Scopes
Expected representation: one Natural Person, multiple Accounts, one Account
per Scope, and optional Synonymity Assertions linking account records.
Checks:
- Each account keeps its source and lifecycle state.
- Linking accounts does not merge them destructively.
- Different scopes can use different identifiers.
S03. Enterprise With Sub-Organizations
Frozen source: scenarios/ScenarioTests.md lines 36–47; SHA-256 76282210f7df6bf26635ede205ed08215908eb82f8c84d411178bc01516a3f4d.
Historical wording; this is not a current model definition.
## S03. Enterprise With Sub-Organizations
Expected representation: Organization actors linked by structural
relationships, plus Accounts and Membership relationships scoped to relevant
systems.
Checks:
- Sub-organization is not automatically a tenant.
- Legal entity status is modeled separately.
- Membership and administration relationships are explicit.
S04. Vendor Tenant Serving Customer Tenants
Frozen source: scenarios/ScenarioTests.md lines 48–59; SHA-256 f674aa6466c45664d941359e2016a5f43a9ef58f58f1299f1ecb39003ef9a0c3.
Historical wording; this is not a current model definition.
## S04. Vendor Tenant Serving Customer Tenants
Expected representation: Vendor and Customer relationship roles between
Organization actors; Tenant scopes for platform isolation; optional
Administration relationships for delegated support.
Checks:
- Customer is not collapsed into Tenant.
- Vendor is not collapsed into Realm.
- Cross-tenant administration is scoped and evidenced.
S05. Customer Organization With Delegated Administrators
Frozen source: scenarios/ScenarioTests.md lines 60–70; SHA-256 40271bc925011808c60854faf342853ed48ff737afc7885921b62696b02c69d3.
Historical wording; this is not a current model definition.
## S05. Customer Organization With Delegated Administrators
Expected representation: Organization actor, Tenant scope, administrator
Accounts, Delegation and Administration relationships.
Checks:
- Admin rights are relationships, not just group names.
- Delegation has source, target, scope, and lifecycle state.
- Authorization projection can consume the relationship separately.
S06. Family With Guardian And Dependent Accounts
Frozen source: scenarios/ScenarioTests.md lines 71–82; SHA-256 a3f0705f7168974632f544891e08403fdcdaa2b205f40ae899bc0483af445106.
Historical wording; this is not a current model definition.
## S06. Family With Guardian And Dependent Accounts
Expected representation: Family or Household collective actor, Natural Person
actors, guardian/dependent relationships, child Accounts, and privacy
constraints.
Checks:
- Guardian relationship is not generic membership.
- Household and legal family can differ.
- Privacy-sensitive links can be scoped.
S07. Spontaneous Interest Group
Frozen source: scenarios/ScenarioTests.md lines 83–93; SHA-256 b4d3ed3df96d57dfc9defcb0395c134e500c79375972ccb978c2abfb64da7247.
Historical wording; this is not a current model definition.
## S07. Spontaneous Interest Group
Expected representation: Community or Group collective actor, Membership
relationships, optional moderator Administration relationships.
Checks:
- Informal group does not need legal entity or tenant semantics.
- Moderation is not the same as membership.
- Group identity can exist without strong real-world identity proofing.
S08. Community With Members, Moderators, And Followers
Frozen source: scenarios/ScenarioTests.md lines 94–105; SHA-256 83de4820c3662f015970f7360ceb1278bca3fa8bf63037826316d63643e580ae.
Historical wording; this is not a current model definition.
## S08. Community With Members, Moderators, And Followers
Expected representation: Community actor; Membership relationships for
members; Administration or moderation relationships for moderators; Following
relationships for followers.
Checks:
- Follower is not a member unless the source says so.
- Moderator authority is explicit and scoped.
- Public profile can differ from account.
S09. Social Media Follower Graph
Frozen source: scenarios/ScenarioTests.md lines 106–116; SHA-256 fd342efc3924c194784c48d937333426addcac7e8404a1834881e284937777b3.
Historical wording; this is not a current model definition.
## S09. Social Media Follower Graph
Expected representation: Actor or Persona profiles connected by Following
relationships in a social Scope.
Checks:
- Following is directed.
- Following does not imply affiliation, membership, trust, or authorization.
- Pseudonymous profiles can remain scoped.
S10. Bot Or Service Account Acting For An Organization
Frozen source: scenarios/ScenarioTests.md lines 117–127; SHA-256 b7671fae9cd9c0c2070588558e72fc34e6a40a449b088738761253df23955228.
Historical wording; this is not a current model definition.
## S10. Bot Or Service Account Acting For An Organization
Expected representation: Artificial Agent actor, Service Account, Organization
actor, Representation or Delegation relationship, and Credential records.
Checks:
- Bot is not a natural person.
- Service account has an owner or responsible actor.
- Delegated authority has bounded scope and lifecycle.
S11. AI Agent Acting Under Delegated Authority
Frozen source: scenarios/ScenarioTests.md lines 128–139; SHA-256 c26e3ad239e21e320a65dcee09b95260db582d26ff08c3b7cf537577c9501275.
Historical wording; this is not a current model definition.
## S11. AI Agent Acting Under Delegated Authority
Expected representation: Artificial Agent actor, Account or Service Account,
Delegation relationship from a Natural Person or Organization, and audit or
evidence references for actions.
Checks:
- Delegation identifies who granted authority.
- Agent actions can be attributed without treating the agent as the person.
- Authorization projection can include delegated context.
S12. Weak Identity Match From Imported Data
Frozen source: scenarios/ScenarioTests.md lines 140–150; SHA-256 b5f26ea04922d59bfe1c7dd240a2348e4afc6cc45a257ea5dfbb733e614649d5.
Historical wording; this is not a current model definition.
## S12. Weak Identity Match From Imported Data
Expected representation: source Identity Records linked by a weak Synonymity
Assertion with method, evidence, confidence, scope, and lifecycle state.
Checks:
- Weak match does not merge accounts.
- Consumers can reject or quarantine weak links.
- Evidence source remains visible.
S13. Strong Account Link After Explicit Verification
Frozen source: scenarios/ScenarioTests.md lines 151–161; SHA-256 4d4ec21f4e4a70bd1095e0baa7691c39497f970fab42a073683a0200c5ee5949.
Historical wording; this is not a current model definition.
## S13. Strong Account Link After Explicit Verification
Expected representation: Accounts linked by a strong Synonymity Assertion or
Account Link relationship, with verification evidence and revocation path.
Checks:
- Strong link is still scoped.
- Verification method is recorded.
- Revocation or unlinking is possible.
S14. Pseudonymous Profile Linked Only Within A Restricted Scope
Frozen source: scenarios/ScenarioTests.md lines 162–172; SHA-256 01618fb5fc15400461ceb46402bc5c908fdd3555c3e2aa04adb964faf466bab1.
Historical wording; this is not a current model definition.
## S14. Pseudonymous Profile Linked Only Within A Restricted Scope
Expected representation: Persona or Profile with Scoped Identifier and
privacy-limited Synonymity Assertion visible only inside an allowed Scope.
Checks:
- Public consumers cannot infer the hidden link.
- The pseudonym can have relationships independent of legal identity.
- Scope boundaries are explicit.
S15. Organization Represented By A Legal Entity And Operational Tenants
Frozen source: scenarios/ScenarioTests.md lines 173–184; SHA-256 a809f4bae8f243f9034887ad2c16903449999ae695c2fc1c4fc089cf9b7020a0.
Historical wording; this is not a current model definition.
## S15. Organization Represented By A Legal Entity And Operational Tenants
Expected representation: Organization actor, Legal Entity specialization or
relationship, one or more Tenant scopes, and Representation relationships for
authorized persons or agents.
Checks:
- Legal entity and tenant are separate model elements.
- Multiple tenants can relate to one organization.
- Representation authority is scoped and evidenced.
Conflict: User
Frozen source: terminology/TerminologyConflictMap.md lines 6–28; SHA-256 03cc685a840d47b36bf124aa8c1465216dfcb1c463f911dbe5e934b7fa81e3b6.
Historical wording; this is not a current model definition.
## Conflict: User
Problem: `user` can mean a person, account, login credential holder,
application profile, authorization subject, or product-facing actor.
Source evidence:
- SCIM User = provisionable Identity Record (`scim-rfc7643-rfc7644.md`)
- Keycloak/ZITADEL User = Account with credentials (`keycloak-organizations.md`,
`zitadel-organizations-projects.md`)
- OpenFGA `user:` tuple prefix = Authorization Principal id (`openfga-modeling.md`)
- OIDC End-User = implied Natural Person, not modeled (`oidc-core-subject-identifiers.md`)
Canonical stance: do not use `user` as a root concept.
Current mapping rule:
- Provisioning record (SCIM/LDAP) → Identity Record
- Login-enabled product record → Account
- Public/local display → Profile
- Access evaluation → Principal or Authenticated Subject
- Human being → Natural Person
Conflict: Identity
Frozen source: terminology/TerminologyConflictMap.md lines 29–43; SHA-256 acf3297ff3ac425a535639c97c8e9368833d0e4e78225679263bcd5ab6ecbbed.
Historical wording; this is not a current model definition.
## Conflict: Identity
Problem: `identity` can mean selfhood, a directory record, an issuer-bound
subject, a set of claims, a DID, a credential, a profile, or an account.
Source evidence:
- Kratos Identity = traits + credentials (`ory-kratos-keto.md`)
- OIDC developers conflate `sub` with "identity" (`oidc-core-subject-identifiers.md`)
- DID is identifier, not identity record (`did-core.md`)
- VC credentialSubject = claims about subject (`vc-data-model-2.md`)
Canonical stance: avoid bare `identity`. Prefer Identity Record, Identifier,
Claim, Credential, Profile, Persona, or Synonymity Assertion.
Conflict: Account
Frozen source: terminology/TerminologyConflictMap.md lines 44–59; SHA-256 5bc5a473a54d20d4cbba778d5f4508e0655cb755d118583715873b2ca81533a2.
Historical wording; this is not a current model definition.
## Conflict: Account
Problem: account can mean login account, customer billing account, social
media handle, service account, or FOAF online presence.
Source evidence:
- FOAF OnlineAccount is service presence, explicitly not Person (`foaf-agent-person-group-onlineaccount.md`)
- LDAP posixAccount is attribute bundle on person entry (`ldap-rfc4519-inetorgperson-rfc2798.md`)
- ActivityPub `acct:` URI suggests account but actor is richer (`activitypub-actors-followers.md`)
- ZITADEL machine user = Service Account (`zitadel-organizations-projects.md`)
Canonical stance: Account is operational access record in a scope. Billing
records map to Commercial Record; commercial parties use Customer/Vendor roles
and Commercial Relationship.
Conflict: Subject, Principal, Actor
Frozen source: terminology/TerminologyConflictMap.md lines 60–79; SHA-256 5f7282450703c7ab38c6d6b044bf99731c274974dd8ece1785de74bdc1365feb.
Historical wording; this is not a current model definition.
## Conflict: Subject, Principal, Actor
Problem: protocols, authorization engines, and social models overload these terms.
Source evidence:
- OIDC Subject = issuer-scoped identifier (`oidc-core-subject-identifiers.md`)
- SAML Principal = authenticated subject in assertion (`saml-nameid-federation.md`)
- Cedar Principal = typed entity in authorization request (`cedar-principal-action-resource-context.md`)
- Zanzibar/OpenFGA Subject = opaque authz participant (`zanzibar-rebac.md`)
- ActivityPub Actor = server-hosted social entity (`activitypub-actors-followers.md`)
- FOAF Agent = actionable entity, includes Person (`foaf-agent-person-group-onlineaccount.md`)
- GDPR Data Subject = natural person (`gdpr-pseudonymization.md`)
Canonical stance:
- Actor = conceptual participant
- Authenticated Subject = issuer/protocol view
- Authorization Principal = decision-engine projection
Conflict: Tenant, Realm, Organization, Customer
Frozen source: terminology/TerminologyConflictMap.md lines 80–99; SHA-256 3e920b787354989a9cce48cc7b45c915150b215b4fcdfe054b854d9cc9748191.
Historical wording; this is not a current model definition.
## Conflict: Tenant, Realm, Organization, Customer
Problem: multi-tenant products collapse isolation boundaries and commercial actors.
Source evidence:
- Keycloak Realm = hard namespace; Organization = B2B overlay (`keycloak-organizations.md`)
- ZITADEL Organization = customer boundary + org actor (`zitadel-organizations-projects.md`)
- SCIM has no tenant; org is string attribute (`scim-rfc7643-rfc7644.md`)
- Schema.org Organization = collective actor (`schema-org-person-organization-membership.md`)
Canonical stance:
- Tenant = administrative/isolation scope
- Realm = issuer/admin namespace (Scope specialization)
- Organization = collective actor
- Customer = commercial relationship role
Model relationships among them; do not synonymize.
Conflict: Group, Role, Team, Community
Frozen source: terminology/TerminologyConflictMap.md lines 100–119; SHA-256 0a8cd0ebc16563b59014cbaf3e026ae6633f24aa8f26dabe1c2bfebf70b4f3d4.
Historical wording; this is not a current model definition.
## Conflict: Group, Role, Team, Community
Problem: IAM groups, collaboration teams, social communities, and authz member
relations use overlapping labels.
Source evidence:
- LDAP/SCIM Group = entry with member references (`ldap`, `scim` notes)
- ActivityPub Group actor = collective social actor (`activitypub-actors-followers.md`)
- Zanzibar `group#member@user` = authz tuple (`zanzibar-rebac.md`)
- Cerbos derived role from group attribute (`cerbos-abac-derived-roles.md`)
- Schema.org Organization subtypes include SportsTeam (`schema-org` note)
Canonical stance:
- Group = named collection with membership
- Role = capability bundle or relationship label
- Team = collaboration group or org unit
- Community = participation-oriented collective actor
Conflict: Member, Follower, Affiliate
Frozen source: terminology/TerminologyConflictMap.md lines 120–133; SHA-256 59c522c4fa0602246033c3d4bf91b91d718119bc116ad60df9f9c7fda616cefc.
Historical wording; this is not a current model definition.
## Conflict: Member, Follower, Affiliate
Problem: membership, following, affiliation, and authz member relations hide
distinct semantics behind `member`.
Source evidence:
- ActivityPub Follow ≠ membership (`activitypub-actors-followers.md`)
- Schema.org affiliation looser than memberOf (`schema-org-person-organization-membership.md`)
- OpenFGA organization#member = authz projection (`openfga-modeling.md`)
- FOAF member = group membership; knows = acquaintance (`foaf` note)
Canonical stance: use typed relationships with scope and evidence.
Conflict: Profile And Persona
Frozen source: terminology/TerminologyConflictMap.md lines 134–149; SHA-256 7e0380ec397e1c991a40391d366913e7087b4a3f45d416b92c068e34a71450b8.
Historical wording; this is not a current model definition.
## Conflict: Profile And Persona
Problem: profiles are account records, RDF documents, public pages, or VC subjects.
Source evidence:
- WebID profile document = RDF at URI (`webid-solid-profile.md`)
- Kratos traits often called profile informally (`ory-kratos-keto.md`)
- ActivityPub actor profile = public actor representation
- Persona for pairwise/pseudonymous scoped presentation (OIDC, GDPR notes)
Canonical stance:
- Profile = presentation surface in scope
- Persona = deliberate contextual presentation with privacy boundaries
Conflict: Identifier, Credential, Claim
Frozen source: terminology/TerminologyConflictMap.md lines 150–162; SHA-256 ff9f6502a126229aa65ea20817e698285a74df128aa35ea286cf24f87462216e.
Historical wording; this is not a current model definition.
## Conflict: Identifier, Credential, Claim
Problem: tokens and documents bundle all three.
Source evidence:
- OIDC ID Token contains sub (identifier) and claims (`oidc-core-subject-identifiers.md`)
- VC = signed claims with proof (`vc-data-model-2.md`)
- DID verification method = cryptographic credential (`did-core.md`)
- SAML AttributeStatement = claims; NameID = identifier (`saml-nameid-federation.md`)
Canonical stance: identifier refers; credential proves; claim states.
Conflict: Synonymity, Linking, Matching, Merge
Frozen source: terminology/TerminologyConflictMap.md lines 163–177; SHA-256 a714d30d2c1bedfcfe3020fa277c5a6226ec408eebd65efc33aadcba9b825ddf.
Historical wording; this is not a current model definition.
## Conflict: Synonymity, Linking, Matching, Merge
Problem: systems collapse probabilistic matches, verified links, and destructive
merges into one feature.
Source evidence:
- Probabilistic matching → weak assertion (`deterministic-vs-probabilistic-matching.md`)
- OIDC iss+sub binding → strong scoped assertion (`oidc`, `synonymity-assertions` notes)
- Schema.org sameAs = weak web equivalence (`schema-org` note)
- GDPR cross-linking raises identifiability risk (`gdpr-pseudonymization.md`)
- MDM golden record merge = downstream anti-pattern (`deterministic` note)
Canonical stance: synonymity is scoped, evidenced, revocable assertion.
Conflict: Credential (Auth) vs. Verifiable Credential
Frozen source: terminology/TerminologyConflictMap.md lines 178–190; SHA-256 ba22d9bb343b383c489c3887a36dafea1c1b93cbed3d9b799727eb5f2a03ecac.
Historical wording; this is not a current model definition.
## Conflict: Credential (Auth) vs. Verifiable Credential
Problem: "credential" means password, OIDC token, or W3C VC.
Source evidence:
- NIST authenticator/credential (`nist-800-63-4.md`)
- VC Data Model verifiable credential (`vc-data-model-2.md`)
- OpenID4VC bridges OAuth credential terminology with VCs (`openid4vc.md`)
Canonical stance: use Credential with context. VC maps to Credential containing
Claims; login secrets map to Credential (authentication factor).
Conflict: Issuer
Frozen source: terminology/TerminologyConflictMap.md lines 191–203; SHA-256 e7ca901947a8931fb1c427fa217f22bac361c15aa6c57da67580d799676980a7.
Historical wording; this is not a current model definition.
## Conflict: Issuer
Problem: issuer means OIDC OP, VC issuer, SAML IdP, or CSP.
Source evidence:
- OIDC iss claim defines subject namespace (`oidc-core-subject-identifiers.md`)
- VC issuer signs credential (`vc-data-model-2.md`)
- NIST CSP performs proofing (`nist-800-63-4.md`)
Canonical stance: Issuer = Scope authority + Trust Relationship; specify protocol
role when mapping.
Conflict: Customer Account
Frozen source: terminology/TerminologyConflictMap.md lines 204–222; SHA-256 f88abdae039caa5135f7acfb7545747a141fe84703b23f45c918c209d1b73654.
Historical wording; this is not a current model definition.
## Conflict: Customer Account
Problem: `customer account` collapses login account, B2B subscriber organization,
Stripe billing customer, and CRM account into one product noun.
Source evidence:
- Auth0 uses Subscriber for tenant holder, not customer account (`b2b-saas-subscriber-tenancy.md`)
- Stytch: organization is the customer (`b2b-saas-subscriber-tenancy.md`)
- Stripe Customer is billing object with subscriptions, not login (`stripe-customer-billing.md`)
- ZITADEL/Keycloak org-as-tenant has no Customer Account type (`zitadel`, `keycloak` notes)
Canonical stance: **reject Customer Account** as canonical term. Resolve by layer:
- login/access → Account;
- subscribing company → Organization + Customer role + Tenant;
- billing/CRM → Commercial Record;
- vendor↔customer link → Commercial Relationship.
user
Frozen source: terminology/TerminologyInventory.md lines 19–19; SHA-256 0a171d978928b2781f3b7b7f28485e6d6ec53e8fe7808f42629ea7375101ec3c.
Historical wording; this is not a current model definition.
| user | Convenience label only | SCIM, LDAP, Keycloak, ZITADEL, apps | Overloaded. Map by context: SCIM/LDAP User → Identity Record; Keycloak/ZITADEL User → Account. |
account
Frozen source: terminology/TerminologyInventory.md lines 20–20; SHA-256 1901d71fbc43e06b5134161854710bf0f653141bc626bf67d95d4cfd3db0e10f.
Historical wording; this is not a current model definition.
| account | Account | SCIM, LDAP posixAccount, FOAF OnlineAccount, Keycloak | Operational access record in a scope. FOAF separates account from person explicitly. |
identity
Frozen source: terminology/TerminologyInventory.md lines 21–21; SHA-256 779546411717fd6156a3dd3a39eb0869c68d36b10b64fff51e2dc4db9031b422.
Historical wording; this is not a current model definition.
| identity | Identity Record or Claim | Kratos, OIDC, DID, VC, apps | Kratos Identity = traits + credentials. Avoid bare `identity` as root noun. |
identifier
Frozen source: terminology/TerminologyInventory.md lines 22–22; SHA-256 53e9132ea78c16e691b6b0e05371a99aed178d52df6d1e48704b43a40f3193cc.
Historical wording; this is not a current model definition.
| identifier | Identifier | OIDC sub, SAML NameID, LDAP DN, DID, WebID | Value referring within or across scopes. See Scoped Identifier when correlation is limited. |
scoped identifier
Frozen source: terminology/TerminologyInventory.md lines 23–23; SHA-256 e4d333b9c4c275397cbeccd5e0b2eed27b457dff23cca482b42a086885cd2578.
Historical wording; this is not a current model definition.
| scoped identifier | Scoped Identifier | OIDC pairwise, SAML transient, pseudonyms | Meaning limited to RP, sector, tenant, or session. |
credential
Frozen source: terminology/TerminologyInventory.md lines 24–24; SHA-256 c9d2a6c53d2e11f93234cc4fffde742aa82990efc2cb6b83024b929616030248.
Historical wording; this is not a current model definition.
| credential | Credential | NIST, Kratos, OIDC token, VC, DID keys | Proof material. Distinguish VC (claim container) from password/WebAuthn. |
principal
Frozen source: terminology/TerminologyInventory.md lines 26–26; SHA-256 3ab8b5d536f3e1da3f172f95431751a51786291480592b7e2e784338466657ba.
Historical wording; this is not a current model definition.
| principal | Authorization Principal | Cedar, Cerbos, Zanzibar, OpenFGA | Decision-engine participant. OpenFGA `user:` prefix is not a human user. |
end-user
Frozen source: terminology/TerminologyInventory.md lines 27–27; SHA-256 74c3cc32b9d4ce44cf2b61a4673ea73073be69d31900f302937110ab74c43c4c.
Historical wording; this is not a current model definition.
| end-user | Natural Person (inferred) | OIDC | OIDC names the human implicitly; does not model as entity. |
profile
Frozen source: terminology/TerminologyInventory.md lines 28–28; SHA-256 f332b51b59675a5ce79ed19eb9b6ab8d7bbe4e1d651f56099068a1596669db24.
Historical wording; this is not a current model definition.
| profile | Profile | FOAF, WebID/Solid, SCIM attrs, ActivityPub | Presentation or attribute surface. Solid profile is user-controlled data. |
persona
Frozen source: terminology/TerminologyInventory.md lines 29–29; SHA-256 8815441b1d1f825051d8208b5a126c28d1b0a0cec1dc92fc6550b6a79f38eb2d.
Historical wording; this is not a current model definition.
| persona | Persona | proposal, privacy patterns | Contextual presentation; pairwise/pseudonymous profiles map here. |
bot
Frozen source: terminology/TerminologyInventory.md lines 31–31; SHA-256 827962be82a98f1c17ffb62c4f4cd943a66a753d67e5cca0fc8ef77756e8ffad.
Historical wording; this is not a current model definition.
| bot | Artificial Agent | ActivityPub Service, apps | Automated actor; may use Service Account. |
service account
Frozen source: terminology/TerminologyInventory.md lines 32–32; SHA-256 64c7a3372e658872cc40799f62c5c3d7d9a8b319340a8134a829ee0a6f6082b0.
Historical wording; this is not a current model definition.
| service account | Service Account | Keycloak, ZITADEL machine user, Kratos | Non-human login or API identity. ZITADEL machine user, Kratos service patterns. |
machine user
Frozen source: terminology/TerminologyInventory.md lines 33–33; SHA-256 5012066796bdd788383852ec7bc34a06a2fa82433dac3afbeca5f625f8b8df13.
Historical wording; this is not a current model definition.
| machine user | Service Account | ZITADEL | Product term for non-human org identity. |
legal entity
Frozen source: terminology/TerminologyInventory.md lines 35–35; SHA-256 da327d376e38707f55e5a1fbcdd4dee8f76bfc6cb4ec2e8468a90079f2ca1a5a.
Historical wording; this is not a current model definition.
| legal entity | Legal Entity | business, compliance | Organization recognized under law; separate from tenant. |
customer
Frozen source: terminology/TerminologyInventory.md lines 36–36; SHA-256 3e7b01c8abe4d58617b4902063eb4f5f14e7cac5da49a8ff778c33f9bc4716a9.
Historical wording; this is not a current model definition.
| customer | Customer (relationship role) | SaaS, vendor models | B2B subscriber org → Organization + Customer role + Tenant. Not Stripe Customer. |
vendor
Frozen source: terminology/TerminologyInventory.md lines 37–37; SHA-256 68a088043e8cb63172b4c57325022708379566e12a9cf605400179c16a4f46b7.
Historical wording; this is not a current model definition.
| vendor | Vendor (relationship role) | SaaS, multi-vendor | Provider role; not realm or tenant. |
subscriber
Frozen source: terminology/TerminologyInventory.md lines 38–38; SHA-256 3194121265ab0f7be752878e2168006b71c72b9f200f1e5e02aac4f078de5bf4.
Historical wording; this is not a current model definition.
| subscriber | Organization + Customer role | Auth0 B2B SaaS | Convenience label only; not canonical. |
stripe customer
Frozen source: terminology/TerminologyInventory.md lines 39–39; SHA-256 925da008d6dd0d1187f038d5bce0a3d6b6d52709672c0c7393f5b538eb65a389.
Historical wording; this is not a current model definition.
| stripe customer | Commercial Record | Stripe, billing | Billing object; link to Tenant via metadata. Not Account. |
payment method / pm_xxx
Frozen source: terminology/TerminologyInventory.md lines 40–40; SHA-256 1877175fcb5e0ce79e8d9145afd4ea37c10cbe9b03a4896568e868a2c38ae9ed.
Historical wording; this is not a current model definition.
| payment method / pm_xxx | Payment Instrument Reference | Stripe, Adyen | Tokenized provider reference; not Credential; not CHD in canon. |
pan / cvv / chd
Frozen source: terminology/TerminologyInventory.md lines 42–42; SHA-256 84eacf96d9ff1a172086a00c1ecf31e94f5b594ee4dce3559e8ccd2525ab6b9c.
Historical wording; this is not a current model definition.
| pan / cvv / chd | Out of canon | PCI DSS | Downstream PCI vault only. |
crm account
Frozen source: terminology/TerminologyInventory.md lines 47–47; SHA-256 fae0815710a180822daf1af506d5fc59210049f8c5e2382e4094326b64a3e47f.
Historical wording; this is not a current model definition.
| crm account | Commercial Record | Salesforce, CRM | Commercial record; not login Account. |
customer account
Frozen source: terminology/TerminologyInventory.md lines 48–48; SHA-256 86c081e76edc36dd60d4c7c2db34ba23506e1e5b1e174459cd68eb65b913cfa2.
Historical wording; this is not a current model definition.
| customer account | Resolve by layer | billing, IAM, CRM | Not canonical — see TerminologyConflictMap. |
commercial relationship
Frozen source: terminology/TerminologyInventory.md lines 50–50; SHA-256 295a513939a88bc3fe49df82b43a20b0e89409b1969672a9a627fc63e6265f4c.
Historical wording; this is not a current model definition.
| commercial relationship | Commercial Relationship | vendor/customer SaaS | Vendor-to-customer typed relationship. |
beneficial owner
Frozen source: terminology/TerminologyInventory.md lines 52–52; SHA-256 5c1d61373f92b79b054fe3d605a5d8171b2af91ebc9b3636f7b07015b3ce85f0.
Historical wording; this is not a current model definition.
| beneficial owner | Beneficial Owner + Beneficial Ownership Relationship | KYC/AML, FinCEN CDD, FATF R24 | Natural person behind legal entity customer; dedicated relationship type with ownership/control prongs. |
beneficial ownership
Frozen source: terminology/TerminologyInventory.md lines 53–53; SHA-256 8520301fabb9a30b9055f47f6b8b957636038fe4f6ec4a34761cfd233780d40a.
Historical wording; this is not a current model definition.
| beneficial ownership | Beneficial Ownership Relationship | FinCEN CDD, BOI, Open Ownership | Regulated Natural Person → Organization/Legal Entity linkage; not Ownership subtype. |
lei
Frozen source: terminology/TerminologyInventory.md lines 54–54; SHA-256 30a480ef227a05028bea2c34eb48bd0e892095df0f69ab496827932e67578b10.
Historical wording; this is not a current model definition.
| lei | Registry Identifier (regulatory_global) | GLEIF, ISO 17442, ICD 0199 | Legal entity identifier with annual renewal. |
duns
Frozen source: terminology/TerminologyInventory.md lines 55–55; SHA-256 e0b1fc126792ef64cf0a52bc555df0d32fee966a8a092cfdc3a93020d4feb7d9.
Historical wording; this is not a current model definition.
| duns | Proxy Commercial Identifier | D&B, ICD 0060 | Commercial-proxy registry identifier. |
uei
Frozen source: terminology/TerminologyInventory.md lines 56–56; SHA-256 20ba5293b13576bc0a7f5a1abde3a3eed2a056d43e34f2451196b9100e8338a3.
Historical wording; this is not a current model definition.
| uei | Registry Identifier (government_registry) | SAM.gov | US federal entity identifier. |
company registration number
Frozen source: terminology/TerminologyInventory.md lines 57–57; SHA-256 837e7698d5f10320661deea52464e849bcfb001472056c75563aded71989c8c4.
Historical wording; this is not a current model definition.
| company registration number | Registry Identifier (government_registry) | national registers, ALEI | Authoritative incorporating-register identifier. |
alei / ibrn
Frozen source: terminology/TerminologyInventory.md lines 58–58; SHA-256 222c1e86c484f60381795e6ba63bbbd684ce1b81eea5d2452ff3ec5a5bdf1dc3.
Historical wording; this is not a current model definition.
| alei / ibrn | Registry Identifier (government_registry) | ISO 8000-116 | Authoritative legal entity identifier from government register. |
iso 6523 / icd
Frozen source: terminology/TerminologyInventory.md lines 59–59; SHA-256 03da1b9755c903ab6c7d865a98c27223f9d7477629602c635394956f3404dc31.
Historical wording; this is not a current model definition.
| iso 6523 / icd | Registry Identifier scheme | ISO/IEC 6523, PEPPOL | ICD + organization identifier encoding. |
control_basis
Frozen source: terminology/TerminologyInventory.md lines 71–71; SHA-256 7923f00e6a10cdd05fd7b3bc8a5013fc837a36bd1f984fb84fc8f4447e147a7c.
Historical wording; this is not a current model definition.
| control_basis | Beneficial Ownership Relationship metadata | FinCEN CDD, EU AMLD | Settled role enum (chief_executive, managing_member, …). |
fincen id
Frozen source: terminology/TerminologyInventory.md lines 73–73; SHA-256 f0bfb45e5363934041ff910a44cd0d69b578679f9c22719365fb0319b314fb78.
Historical wording; this is not a current model definition.
| fincen id | Registry Identifier (government_registry) | BOI | Natural person government registry ID. |
person account
Frozen source: terminology/TerminologyInventory.md lines 74–74; SHA-256 b75fc9b5ca6ef2146e019e342f8565d138eeefccc4b2ee845f010c835d5567eb.
Historical wording; this is not a current model definition.
| person account | Natural Person + Commercial Record | Salesforce B2C | Adapter projection_mode person_account_combined only. |
ncage / cage
Frozen source: terminology/TerminologyInventory.md lines 75–75; SHA-256 cadfb882fc19bda7c60bb8c75e0ed7e2e2b63974037ff07947a8a427d852b9b2.
Historical wording; this is not a current model definition.
| ncage / cage | Registry Identifier (industry_association) | defense procurement | Industry association authority class. |
crm account
Frozen source: terminology/TerminologyInventory.md lines 79–79; SHA-256 9b1dcdfbe61b780895d51b439da2dffc0df0df7cc4dfb4d57de7dd3f8eb30d0e.
Historical wording; this is not a current model definition.
| crm account | Commercial Record | Salesforce | Company/household commercial record. |
fluid identity
Frozen source: terminology/TerminologyInventory.md lines 80–80; SHA-256 3c171e79b1f6966812977a4de526300db7dea729ac4bef4f86737575e836d54e.
Historical wording; this is not a current model definition.
| fluid identity | Persona / weak binding | theory | Low commercial stake; intentional mutability. |
tenant
Frozen source: terminology/TerminologyInventory.md lines 82–82; SHA-256 8ea48ff21a23148aea6923f844adb270f01af86f334bd9fd2e6642e6ac35dc40.
Historical wording; this is not a current model definition.
| tenant | Tenant | ZITADEL org, SaaS, Keycloak (informal) | Administrative/isolation scope. Keycloak realm sometimes called tenant. |
realm
Frozen source: terminology/TerminologyInventory.md lines 83–83; SHA-256 faaa0b5ee2eee0c243c2eda3a90df392858d974bfc1df02422a8df0b71276980.
Historical wording; this is not a current model definition.
| realm | Realm | Keycloak | Hard identity/admin namespace. Candidate Scope specialization. |
scope
Frozen source: terminology/TerminologyInventory.md lines 84–84; SHA-256 05dc1d57cb500d7c30328b063db392cb4e4be19479c2596f739b474e640ec6bb.
Historical wording; this is not a current model definition.
| scope | Scope | OIDC, Cerbos, OpenFGA store, proposal | Boundary for meaning, policy, or correlation. |
namespace
Frozen source: terminology/TerminologyInventory.md lines 85–85; SHA-256 348ff0b2f98a4a7b53947188a958999ec7779c636bb8fcca133075dabe031750.
Historical wording; this is not a current model definition.
| namespace | Scope | LDAP dc, Keto/OpenFGA, DID method | Naming or authorization partition. |
instance
Frozen source: terminology/TerminologyInventory.md lines 86–86; SHA-256 a091b4ac6ab9f52f953832634e1f942fd000ead687ce46a57d4983fd7e79f33d.
Historical wording; this is not a current model definition.
| instance | Scope | ZITADEL | Deployment-level boundary above organizations. |
project
Frozen source: terminology/TerminologyInventory.md lines 87–87; SHA-256 329b17d1d24ed30b039ced9d3e3277cb23e49ea59f4c7ac7acf9ddae3e83dfc7.
Historical wording; this is not a current model definition.
| project | Application Scope | ZITADEL | Application/product container within org. |
role
Frozen source: terminology/TerminologyInventory.md lines 93–93; SHA-256 bf4b3c078725e3a9b4c661c358df673204d21865de9386223c00682de7a76d2a.
Historical wording; this is not a current model definition.
| role | Role | Keycloak, ZITADEL, Cedar, Cerbos, Schema.org OrganizationRole | Capability bundle or relationship label. Cerbos derived role may hide Ownership. |
grant
Frozen source: terminology/TerminologyInventory.md lines 94–94; SHA-256 ca2c9b2882bd176716d5f40b570f7d142e820881529353bdd9829ca2fff5acfd.
Historical wording; this is not a current model definition.
| grant | Role assignment | ZITADEL | Project role assignment; map to Delegation-like relationship. |
member
Frozen source: terminology/TerminologyInventory.md lines 95–95; SHA-256 a6600f7dd9604883a0c366467ad89a90ceee68aefbe6aca09067ada754baae23.
Historical wording; this is not a current model definition.
| member | Membership Relationship | SCIM, LDAP, FOAF, Schema.org, Zanzibar | Relationship edge, not a noun for the participant. |
affiliation
Frozen source: terminology/TerminologyInventory.md lines 96–96; SHA-256 06170379083ad57eb7ec1dee172d3f2e370140f32c1e8b3ccf5a700c3fffdb66.
Historical wording; this is not a current model definition.
| affiliation | Affiliation Relationship | Schema.org, FOAF knows | Looser than membership. FOAF knows is weak social affiliation. |
follower
Frozen source: terminology/TerminologyInventory.md lines 97–97; SHA-256 62256899610e66f10a97b6f7011d52ff02ce79f6d4060c0d403bc8a520f3e6ff.
Historical wording; this is not a current model definition.
| follower | Following Relationship | ActivityPub | Directed social subscription; not membership or authz. |
follow
Frozen source: terminology/TerminologyInventory.md lines 98–98; SHA-256 1c77e34bdf1206d046ef8eee40d4a94393faf67a5af97821834b12b9f9bcea81.
Historical wording; this is not a current model definition.
| follow | Following Relationship | ActivityPub | Activity establishing follower edge. |
owner
Frozen source: terminology/TerminologyInventory.md lines 99–99; SHA-256 78b48373de87a79fc4d67b68b30f7a16c2fbab573b24ddd44f8cfb13487e6896.
Historical wording; this is not a current model definition.
| owner | Ownership Relationship | Zanzibar, Cerbos derived | Control/responsibility. Cerbos may encode as attribute not relationship. |
administrator
Frozen source: terminology/TerminologyInventory.md lines 100–100; SHA-256 8325a4edc6753be9dadce60ad0fcfd5b46ad0528e0efc0ea9ad3a8d116a93f76.
Historical wording; this is not a current model definition.
| administrator | Administration Relationship | IAM, ZITADEL grants | Delegated management in scope. |
delegation
Frozen source: terminology/TerminologyInventory.md lines 101–101; SHA-256 538948038bf8b7c7e6c562238017e8efd2c4d2112e542bc9cb7d1d47d521df09.
Historical wording; this is not a current model definition.
| delegation | Delegation Relationship | Cedar context, agents | Bounded authority grant. Cedar context may carry delegatedBy. |
representation
Frozen source: terminology/TerminologyInventory.md lines 102–102; SHA-256 1a93d64d4e3f608806754d3889b9655d0083e2f5ce92db14780c8513fbfff419.
Historical wording; this is not a current model definition.
| representation | Representation Relationship | SCIM manager, DID controller | Acting on behalf of another. DID controller may differ from subject. |
trust
Frozen source: terminology/TerminologyInventory.md lines 103–103; SHA-256 3a652a6f5721c7c3616ea4fb93db81e7514538d1f2052eb00cd3333e881dd3c6.
Historical wording; this is not a current model definition.
| trust | Trust Relationship | federation, VC, DID | Reliance on issuer/verifier; federation metadata trust. |
claim
Frozen source: terminology/TerminologyInventory.md lines 104–104; SHA-256 1ce7bcc854285f598ad1927182e0821d7db9e9fb2a09cbd0d7e743549ca2b37e.
Historical wording; this is not a current model definition.
| claim | Claim | OIDC, SAML attributes, VC | Statement by issuer. SAML AttributeStatement → Claim. |
assurance
Frozen source: terminology/TerminologyInventory.md lines 106–106; SHA-256 130c61dcb0687328ed992999688e1f37c07958e258a96db49787d1d9fce90dad.
Historical wording; this is not a current model definition.
| assurance | Assurance Level | NIST IAL/AAL/FAL | Orthogonal identity, authentication, federation confidence. |
identifier binding
Frozen source: terminology/TerminologyInventory.md lines 107–107; SHA-256 384043ffa3353df53a5a4769971853cedccf232fe72d1a8044d1dd3b53cfc378.
Historical wording; this is not a current model definition.
| identifier binding | Identifier Binding | OIDC iss+sub, WebID-OIDC, SAML | Assertion that identifier refers to target in scope. |
synonymity
Frozen source: terminology/TerminologyInventory.md lines 108–108; SHA-256 58d9d36c18fda3e8df9a74af3c2fae1f3103a6f62df39d0b5db951ce3b6fe5e3.
Historical wording; this is not a current model definition.
| synonymity | Synonymity Assertion | entity resolution, OIDC linking, schema.org sameAs | Scoped evidenced equivalence. sameAs is weak by default. |
weak match
Frozen source: terminology/TerminologyInventory.md lines 109–109; SHA-256 3f35848a32547aa86fe3ec9e7e755e4fd6392d71ef3d683953df7b08a5c1dd95.
Historical wording; this is not a current model definition.
| weak match | Weak Synonymity Assertion | probabilistic matching | Probabilistic link; never destructive merge. |
strong link
Frozen source: terminology/TerminologyInventory.md lines 110–110; SHA-256 5f0902c8bed0e10535d0f76427677ac135a5c09b10b223aa49dbe05d8fc6c468.
Historical wording; this is not a current model definition.
| strong link | Strong Synonymity Assertion | deterministic match, verified linking | Authoritative or verified; still scoped. |
same_as
Frozen source: terminology/TerminologyInventory.md lines 111–111; SHA-256 9236ea638789b858a465b91a73dfb82c2f91434f04d7fe3bb0bcdfa623c6e951.
Historical wording; this is not a current model definition.
| same_as | Synonymity Assertion (strong) | synonymity model | High-confidence equivalence relation type. |
probably_same_as
Frozen source: terminology/TerminologyInventory.md lines 112–112; SHA-256 1ce7ba621eeb91881b9be16c1e87ce7a78a2a1dd26a0ff7da82b6d3fa04f2069.
Historical wording; this is not a current model definition.
| probably_same_as | Synonymity Assertion (weak) | probabilistic matching | Probabilistic equivalence relation type. |
linked_to
Frozen source: terminology/TerminologyInventory.md lines 113–113; SHA-256 33b998acec8a52176199992c4d0f5d1ca9016d586682e8fa5d18dbdd27957181.
Historical wording; this is not a current model definition.
| linked_to | Synonymity Assertion (operational) | account linking | Convenience link without semantic sameness claim. |
pseudonym
Frozen source: terminology/TerminologyInventory.md lines 114–114; SHA-256 01ebfceff32122591e256df20f312f68881ef3e6d4ebfc5738cdfa4cc28d3d69.
Historical wording; this is not a current model definition.
| pseudonym | Pseudonymous Identifier | GDPR, OIDC pairwise | Limits cross-scope correlation. |
pairwise subject
Frozen source: terminology/TerminologyInventory.md lines 115–115; SHA-256 508a529137ad7a0e7f1409063b306cad3bb1f8aa1c9c15f179c21ab657f46d33.
Historical wording; this is not a current model definition.
| pairwise subject | Scoped Identifier | OIDC | RP-specific sub preventing global correlation. |
relationship tuple
Frozen source: terminology/TerminologyInventory.md lines 116–116; SHA-256 3cab1bbb2dfc5afd3dcde230e104ddd95e67ccddc46fb2bbcc38f99103a55f49.
Historical wording; this is not a current model definition.
| relationship tuple | Relationship Tuple | Zanzibar, OpenFGA, Keto | Authz projection: subject#relation@object. |
policy
Frozen source: terminology/TerminologyInventory.md lines 117–117; SHA-256 13bcf330fb1989abf5ba4d7c673d2c3a646480236f81792abadb74afa660b983.
Historical wording; this is not a current model definition.
| policy | Authorization Projection | Cedar, Cerbos | Rule artifact; downstream of canon model. |
lifecycle state
Frozen source: terminology/TerminologyInventory.md lines 118–118; SHA-256 b39c636369a3c10a22a75c8c686d145f54addfd5720ae90da49321571406d6c6.
Historical wording; this is not a current model definition.
| lifecycle state | Lifecycle State | SCIM active, SSF/RISC events, VC status | Applies to records, credentials, relationships, assertions. |
subscriber
Frozen source: terminology/TerminologyInventory.md lines 119–119; SHA-256 778a574609c40787ae9fec045e791faafd3d39b49fd187b3c10bc6dad0133e4c.
Historical wording; this is not a current model definition.
| subscriber | Account / Identity Record | NIST | Enrolled party at CSP; not synonymous with Natural Person until IAL binding. |
issuer
Frozen source: terminology/TerminologyInventory.md lines 120–120; SHA-256 036456fa64e621bcbf2df81938ec5e5bce4af61c757456935846ef3c2c026282.
Historical wording; this is not a current model definition.
| issuer | Scope + Trust Relationship | OIDC iss, VC issuer, SAML IdP | Namespace authority for identifiers and claims. |
relying party
Frozen source: terminology/TerminologyInventory.md lines 121–121; SHA-256 36a83f3b965a6b2e71938360eb02a5ed64bd665797952d5f592b535e73cfa436.
Historical wording; this is not a current model definition.
| relying party | Scope | OIDC RP, SAML SP, NIST | Consumer of assertions; RP-local account binding. |
nameid
Frozen source: terminology/TerminologyInventory.md lines 122–122; SHA-256 dbe31e5c4483f1b3f8c83c7abe1239137c7da04456f601d8550035a0c308df12.
Historical wording; this is not a current model definition.
| nameid | Identifier | SAML | Format attribute determines persistence and privacy semantics. |
distinguished name
Frozen source: terminology/TerminologyInventory.md lines 123–123; SHA-256 ac1bda1aaeb885049b4ae754e1a507b1e872321069f4ca1a3fc3617660d90454.
Historical wording; this is not a current model definition.
| distinguished name | Identifier | LDAP | Compound locator in directory namespace. |
externalid
Frozen source: terminology/TerminologyInventory.md lines 124–124; SHA-256 e1872cf38aa8e72a824036d017710553cf8ea6f990ef05217c2e972e77c6a978.
Historical wording; this is not a current model definition.
| externalid | Identifier | SCIM | Client-supplied cross-system correlation key. |
traits
Frozen source: terminology/TerminologyInventory.md lines 125–125; SHA-256 aadb34d5ce8bc3500c5a4d49641d87b11b5da9a481b27dbe0d436d5c0e95117f.
Historical wording; this is not a current model definition.
| traits | Profile attributes | Kratos | Schema-validated identity attributes. |
verification method
Frozen source: terminology/TerminologyInventory.md lines 126–126; SHA-256 ade6d356c8a8d8db36f1991f72e711738d9281166feda19b6bf5a5ef341d2f10.
Historical wording; this is not a current model definition.
| verification method | Credential | DID Core | Cryptographic key in DID document. |
verifiable credential
Frozen source: terminology/TerminologyInventory.md lines 127–127; SHA-256 10b80fe4d8c1fd5880c5fb3f626bfff061b2fa2457d93bcaeaa9a6c5d27a69d3.
Historical wording; this is not a current model definition.
| verifiable credential | Credential + Claim | VC Data Model | Signed claim set; distinct from login credential. |
verifier
Frozen source: terminology/TerminologyInventory.md lines 129–129; SHA-256 d37d10d4b1113114369aa128754a243e56f9ee71e5f95d5d9f966d75fe94088b.
Historical wording; this is not a current model definition.
| verifier | Scope (evaluation role) | VC, OpenID4VC | Validates presentations. |
did
Frozen source: terminology/TerminologyInventory.md lines 130–130; SHA-256 4de4b5bba75e89eb1ad4dc0525dc0eeb3eb1102e26c3535c0e85c41a68a68551.
Historical wording; this is not a current model definition.
| did | Identifier | DID Core | Decentralized identifier with method-specific resolution. |
webid
Frozen source: terminology/TerminologyInventory.md lines 131–131; SHA-256 e08c6ed7932919efd4c8f8ae55161be7a02e983d667cf3359fcff0affde44a1b.
Historical wording; this is not a current model definition.
| webid | Identifier | WebID/Solid | HTTP URI identifying agent with dereferenceable profile. |
pseudonymization
Frozen source: terminology/TerminologyInventory.md lines 133–133; SHA-256 157015a6434ede26ec98e5b223c0d07e1cbf3f9e791ede4c11b8b2958bb67963.
Historical wording; this is not a current model definition.
| pseudonymization | Processing pattern | GDPR | Technique; maps to Scoped Identifier + separated re-id key. |
tuple (authz)
Frozen source: terminology/TerminologyInventory.md lines 135–135; SHA-256 89a5e53a0468189c92022352aac36ccf34b62a8a34b49c13241eb5fa91aa830c.
Historical wording; this is not a current model definition.
| tuple (authz) | Relationship Tuple | Zanzibar | Authorization fact, not social relationship. |
derived role
Frozen source: terminology/TerminologyInventory.md lines 137–137; SHA-256 cbfaa9a627d2d32e194e4301e908fd193eb67c788ac3afad98079ce92e898fce.
Historical wording; this is not a current model definition.
| derived role | Role (computed) | Cerbos | Role from attributes; should trace to Relationship when possible. |
contextual tuple
Frozen source: terminology/TerminologyInventory.md lines 138–138; SHA-256 5b1c5f8c2795fc54d61f319bd4c6238538588fa4026e779d0ed615e998133218.
Historical wording; this is not a current model definition.
| contextual tuple | Delegation context | OpenFGA | Ephemeral authz fact at check time. |
sameas
Frozen source: terminology/TerminologyInventory.md lines 139–139; SHA-256 be040500605effc4252c681b4b06d22cc0a7f37fbf622b0987690f4f8d39c86a.
Historical wording; this is not a current model definition.
| sameas | Weak Synonymity Assertion | Schema.org | Informal web equivalence; not strong link without evidence. |
assurance level change
Frozen source: terminology/TerminologyInventory.md lines 141–141; SHA-256 1b1531452b8b67df5a400492a351662c05da740832cc507356df0f1414b40c2b.
Historical wording; this is not a current model definition.
| assurance level change | Assurance Level update | SSF/CAEP | Event affecting IAL/AAL/FAL metadata. |