info-tech-canon/infospace/assimilation/canon-federation/views/itc-org.md
tegwick 372f671eef
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Distribute frozen federation corpus by concept destination
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b
2026-09-06 00:44:37 +02:00

905 lines
39 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# itc-org provenance reading index
Historical input only. Current canon and ADR-006 override superseded assertions.
- [research/CorpusIndex.md](../source/research/CorpusIndex.md) — d110cd1f6653.
- [research/README.md](../source/research/README.md) — 1ab93b1176ac.
- [research/ResearchSeed.md](../source/research/ResearchSeed.md) — 1e432ff04d17.
- [research/authorization-relationships/cedar-principal-action-resource-context.md](../source/research/authorization-relationships/cedar-principal-action-resource-context.md) — 1932a8632dd3.
- [research/authorization-relationships/cerbos-abac-derived-roles.md](../source/research/authorization-relationships/cerbos-abac-derived-roles.md) — c35f15042d45.
- [research/authorization-relationships/openfga-modeling.md](../source/research/authorization-relationships/openfga-modeling.md) — e2d03ddfa7be.
- [research/authorization-relationships/zanzibar-rebac.md](../source/research/authorization-relationships/zanzibar-rebac.md) — 1f736195ab4b.
- [research/commercial-identity/beneficial-ownership-kyc-boi.md](../source/research/commercial-identity/beneficial-ownership-kyc-boi.md) — 602aad062291.
- [research/commercial-identity/commercial-identity-nuance-settlement.md](../source/research/commercial-identity/commercial-identity-nuance-settlement.md) — cabb54601ee7.
- [research/commercial-identity/commercial-identity-synthesis.md](../source/research/commercial-identity/commercial-identity-synthesis.md) — ac70ecdb2046.
- [research/commercial-identity/commercial-trust-binding-theory.md](../source/research/commercial-identity/commercial-trust-binding-theory.md) — fc7be6f0641b.
- [research/commercial-identity/crm-pipeline-commitment-threshold.md](../source/research/commercial-identity/crm-pipeline-commitment-threshold.md) — 459828097e09.
- [research/commercial-identity/duns-commercial-credit-identity.md](../source/research/commercial-identity/duns-commercial-credit-identity.md) — b33b789b047f.
- [research/commercial-identity/eidas-eudi-legal-person-wallet.md](../source/research/commercial-identity/eidas-eudi-legal-person-wallet.md) — be8b05990cd0.
- [research/commercial-identity/kyc-aml-commercial-identity-binding.md](../source/research/commercial-identity/kyc-aml-commercial-identity-binding.md) — 5d3f63465cd7.
- [research/commercial-identity/legal-person-agency-contract.md](../source/research/commercial-identity/legal-person-agency-contract.md) — c3110cc62b49.
- [research/commercial-identity/lei-gleif-legal-entity-identifier.md](../source/research/commercial-identity/lei-gleif-legal-entity-identifier.md) — ef2ba7156f6d.
- [research/commercial-identity/payment-credential-pci-boundary.md](../source/research/commercial-identity/payment-credential-pci-boundary.md) — bcacaee7090c.
- [research/commercial-identity/registry-identifier-subtypes.md](../source/research/commercial-identity/registry-identifier-subtypes.md) — 1a621787a869.
- [research/commercial-identity/reputation-assurance-gradient.md](../source/research/commercial-identity/reputation-assurance-gradient.md) — 0c992d05657d.
- [research/commercial-identity/salesforce-crm-commercial-record.md](../source/research/commercial-identity/salesforce-crm-commercial-record.md) — 52bf8c8dbbd7.
- [research/commercial-subscription/b2b-saas-subscriber-tenancy.md](../source/research/commercial-subscription/b2b-saas-subscriber-tenancy.md) — 133bf4325a7c.
- [research/commercial-subscription/stripe-customer-billing.md](../source/research/commercial-subscription/stripe-customer-billing.md) — bb5c8fe3cab7.
- [research/identity-provisioning/keycloak-organizations.md](../source/research/identity-provisioning/keycloak-organizations.md) — 09c43cdc9ecf.
- [research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md](../source/research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md) — c3f3323a3f25.
- [research/identity-provisioning/ory-kratos-keto.md](../source/research/identity-provisioning/ory-kratos-keto.md) — 5cd12c38f8d3.
- [research/identity-provisioning/scim-rfc7643-rfc7644.md](../source/research/identity-provisioning/scim-rfc7643-rfc7644.md) — c5c03952ac2f.
- [research/identity-provisioning/zitadel-organizations-projects.md](../source/research/identity-provisioning/zitadel-organizations-projects.md) — f4b1b6f4cce3.
- [research/social-community-graphs/activitypub-actors-followers.md](../source/research/social-community-graphs/activitypub-actors-followers.md) — 8b28bfc385d1.
- [research/social-community-graphs/foaf-agent-person-group-onlineaccount.md](../source/research/social-community-graphs/foaf-agent-person-group-onlineaccount.md) — 4131e7685da5.
- [research/social-community-graphs/schema-org-person-organization-membership.md](../source/research/social-community-graphs/schema-org-person-organization-membership.md) — bc274f7cf1ff.
- [research/social-community-graphs/webid-solid-profile.md](../source/research/social-community-graphs/webid-solid-profile.md) — abf0c62e23b0.
- [research/verifiable-claims/did-core.md](../source/research/verifiable-claims/did-core.md) — cbe5fd46e093.
- [research/verifiable-claims/openid4vc.md](../source/research/verifiable-claims/openid4vc.md) — e6fcc0612146.
- [research/verifiable-claims/vc-data-model-2.md](../source/research/verifiable-claims/vc-data-model-2.md) — dae7bc679c6c.
- [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) — 400641667064.
- [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) — 06c8134a399a.
- [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) — 5d22816b0bfe.
## Shared terminology and scenario fragments
### S01. Single Person With One Local Account
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 1324; SHA-256 `0040dd866009ad1199e89f89267e3aab86894859f6ae6d07f393e4f0b8cdb6f5`.
Historical wording; this is not a current model definition.
```text
## S01. Single Person With One Local Account
Expected representation: one Natural Person, one Account in an application
Scope, one local Identifier, one Profile, and one Membership or access
relationship if the account belongs to a group.
Checks:
- The person is not identical to the account.
- The profile is not the credential.
- Authorization can project the account or subject into a Principal.
```
### S02. Person With Multiple Accounts Across Scopes
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 2535; SHA-256 `69cabdc1680936fffd25378d9a1fcaa129c258eeca03663a3c9e9718def6fd59`.
Historical wording; this is not a current model definition.
```text
## S02. Person With Multiple Accounts Across Scopes
Expected representation: one Natural Person, multiple Accounts, one Account
per Scope, and optional Synonymity Assertions linking account records.
Checks:
- Each account keeps its source and lifecycle state.
- Linking accounts does not merge them destructively.
- Different scopes can use different identifiers.
```
### S03. Enterprise With Sub-Organizations
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 3647; SHA-256 `76282210f7df6bf26635ede205ed08215908eb82f8c84d411178bc01516a3f4d`.
Historical wording; this is not a current model definition.
```text
## S03. Enterprise With Sub-Organizations
Expected representation: Organization actors linked by structural
relationships, plus Accounts and Membership relationships scoped to relevant
systems.
Checks:
- Sub-organization is not automatically a tenant.
- Legal entity status is modeled separately.
- Membership and administration relationships are explicit.
```
### S04. Vendor Tenant Serving Customer Tenants
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 4859; SHA-256 `f674aa6466c45664d941359e2016a5f43a9ef58f58f1299f1ecb39003ef9a0c3`.
Historical wording; this is not a current model definition.
```text
## S04. Vendor Tenant Serving Customer Tenants
Expected representation: Vendor and Customer relationship roles between
Organization actors; Tenant scopes for platform isolation; optional
Administration relationships for delegated support.
Checks:
- Customer is not collapsed into Tenant.
- Vendor is not collapsed into Realm.
- Cross-tenant administration is scoped and evidenced.
```
### S05. Customer Organization With Delegated Administrators
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 6070; SHA-256 `40271bc925011808c60854faf342853ed48ff737afc7885921b62696b02c69d3`.
Historical wording; this is not a current model definition.
```text
## S05. Customer Organization With Delegated Administrators
Expected representation: Organization actor, Tenant scope, administrator
Accounts, Delegation and Administration relationships.
Checks:
- Admin rights are relationships, not just group names.
- Delegation has source, target, scope, and lifecycle state.
- Authorization projection can consume the relationship separately.
```
### S06. Family With Guardian And Dependent Accounts
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 7182; SHA-256 `a3f0705f7168974632f544891e08403fdcdaa2b205f40ae899bc0483af445106`.
Historical wording; this is not a current model definition.
```text
## S06. Family With Guardian And Dependent Accounts
Expected representation: Family or Household collective actor, Natural Person
actors, guardian/dependent relationships, child Accounts, and privacy
constraints.
Checks:
- Guardian relationship is not generic membership.
- Household and legal family can differ.
- Privacy-sensitive links can be scoped.
```
### S07. Spontaneous Interest Group
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 8393; SHA-256 `b4d3ed3df96d57dfc9defcb0395c134e500c79375972ccb978c2abfb64da7247`.
Historical wording; this is not a current model definition.
```text
## S07. Spontaneous Interest Group
Expected representation: Community or Group collective actor, Membership
relationships, optional moderator Administration relationships.
Checks:
- Informal group does not need legal entity or tenant semantics.
- Moderation is not the same as membership.
- Group identity can exist without strong real-world identity proofing.
```
### S08. Community With Members, Moderators, And Followers
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 94105; SHA-256 `83de4820c3662f015970f7360ceb1278bca3fa8bf63037826316d63643e580ae`.
Historical wording; this is not a current model definition.
```text
## S08. Community With Members, Moderators, And Followers
Expected representation: Community actor; Membership relationships for
members; Administration or moderation relationships for moderators; Following
relationships for followers.
Checks:
- Follower is not a member unless the source says so.
- Moderator authority is explicit and scoped.
- Public profile can differ from account.
```
### S09. Social Media Follower Graph
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 106116; SHA-256 `fd342efc3924c194784c48d937333426addcac7e8404a1834881e284937777b3`.
Historical wording; this is not a current model definition.
```text
## S09. Social Media Follower Graph
Expected representation: Actor or Persona profiles connected by Following
relationships in a social Scope.
Checks:
- Following is directed.
- Following does not imply affiliation, membership, trust, or authorization.
- Pseudonymous profiles can remain scoped.
```
### S10. Bot Or Service Account Acting For An Organization
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 117127; SHA-256 `b7671fae9cd9c0c2070588558e72fc34e6a40a449b088738761253df23955228`.
Historical wording; this is not a current model definition.
```text
## S10. Bot Or Service Account Acting For An Organization
Expected representation: Artificial Agent actor, Service Account, Organization
actor, Representation or Delegation relationship, and Credential records.
Checks:
- Bot is not a natural person.
- Service account has an owner or responsible actor.
- Delegated authority has bounded scope and lifecycle.
```
### S11. AI Agent Acting Under Delegated Authority
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 128139; SHA-256 `c26e3ad239e21e320a65dcee09b95260db582d26ff08c3b7cf537577c9501275`.
Historical wording; this is not a current model definition.
```text
## S11. AI Agent Acting Under Delegated Authority
Expected representation: Artificial Agent actor, Account or Service Account,
Delegation relationship from a Natural Person or Organization, and audit or
evidence references for actions.
Checks:
- Delegation identifies who granted authority.
- Agent actions can be attributed without treating the agent as the person.
- Authorization projection can include delegated context.
```
### S15. Organization Represented By A Legal Entity And Operational Tenants
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 173184; SHA-256 `a809f4bae8f243f9034887ad2c16903449999ae695c2fc1c4fc089cf9b7020a0`.
Historical wording; this is not a current model definition.
```text
## S15. Organization Represented By A Legal Entity And Operational Tenants
Expected representation: Organization actor, Legal Entity specialization or
relationship, one or more Tenant scopes, and Representation relationships for
authorized persons or agents.
Checks:
- Legal entity and tenant are separate model elements.
- Multiple tenants can relate to one organization.
- Representation authority is scoped and evidenced.
```
### Conflict: User
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 628; SHA-256 `03cc685a840d47b36bf124aa8c1465216dfcb1c463f911dbe5e934b7fa81e3b6`.
Historical wording; this is not a current model definition.
```text
## Conflict: User
Problem: `user` can mean a person, account, login credential holder,
application profile, authorization subject, or product-facing actor.
Source evidence:
- SCIM User = provisionable Identity Record (`scim-rfc7643-rfc7644.md`)
- Keycloak/ZITADEL User = Account with credentials (`keycloak-organizations.md`,
`zitadel-organizations-projects.md`)
- OpenFGA `user:` tuple prefix = Authorization Principal id (`openfga-modeling.md`)
- OIDC End-User = implied Natural Person, not modeled (`oidc-core-subject-identifiers.md`)
Canonical stance: do not use `user` as a root concept.
Current mapping rule:
- Provisioning record (SCIM/LDAP) → Identity Record
- Login-enabled product record → Account
- Public/local display → Profile
- Access evaluation → Principal or Authenticated Subject
- Human being → Natural Person
```
### Conflict: Account
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 4459; SHA-256 `5bc5a473a54d20d4cbba778d5f4508e0655cb755d118583715873b2ca81533a2`.
Historical wording; this is not a current model definition.
```text
## Conflict: Account
Problem: account can mean login account, customer billing account, social
media handle, service account, or FOAF online presence.
Source evidence:
- FOAF OnlineAccount is service presence, explicitly not Person (`foaf-agent-person-group-onlineaccount.md`)
- LDAP posixAccount is attribute bundle on person entry (`ldap-rfc4519-inetorgperson-rfc2798.md`)
- ActivityPub `acct:` URI suggests account but actor is richer (`activitypub-actors-followers.md`)
- ZITADEL machine user = Service Account (`zitadel-organizations-projects.md`)
Canonical stance: Account is operational access record in a scope. Billing
records map to Commercial Record; commercial parties use Customer/Vendor roles
and Commercial Relationship.
```
### Conflict: Subject, Principal, Actor
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 6079; SHA-256 `5f7282450703c7ab38c6d6b044bf99731c274974dd8ece1785de74bdc1365feb`.
Historical wording; this is not a current model definition.
```text
## Conflict: Subject, Principal, Actor
Problem: protocols, authorization engines, and social models overload these terms.
Source evidence:
- OIDC Subject = issuer-scoped identifier (`oidc-core-subject-identifiers.md`)
- SAML Principal = authenticated subject in assertion (`saml-nameid-federation.md`)
- Cedar Principal = typed entity in authorization request (`cedar-principal-action-resource-context.md`)
- Zanzibar/OpenFGA Subject = opaque authz participant (`zanzibar-rebac.md`)
- ActivityPub Actor = server-hosted social entity (`activitypub-actors-followers.md`)
- FOAF Agent = actionable entity, includes Person (`foaf-agent-person-group-onlineaccount.md`)
- GDPR Data Subject = natural person (`gdpr-pseudonymization.md`)
Canonical stance:
- Actor = conceptual participant
- Authenticated Subject = issuer/protocol view
- Authorization Principal = decision-engine projection
```
### Conflict: Tenant, Realm, Organization, Customer
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 8099; SHA-256 `3e920b787354989a9cce48cc7b45c915150b215b4fcdfe054b854d9cc9748191`.
Historical wording; this is not a current model definition.
```text
## Conflict: Tenant, Realm, Organization, Customer
Problem: multi-tenant products collapse isolation boundaries and commercial actors.
Source evidence:
- Keycloak Realm = hard namespace; Organization = B2B overlay (`keycloak-organizations.md`)
- ZITADEL Organization = customer boundary + org actor (`zitadel-organizations-projects.md`)
- SCIM has no tenant; org is string attribute (`scim-rfc7643-rfc7644.md`)
- Schema.org Organization = collective actor (`schema-org-person-organization-membership.md`)
Canonical stance:
- Tenant = administrative/isolation scope
- Realm = issuer/admin namespace (Scope specialization)
- Organization = collective actor
- Customer = commercial relationship role
Model relationships among them; do not synonymize.
```
### Conflict: Group, Role, Team, Community
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 100119; SHA-256 `0a8cd0ebc16563b59014cbaf3e026ae6633f24aa8f26dabe1c2bfebf70b4f3d4`.
Historical wording; this is not a current model definition.
```text
## Conflict: Group, Role, Team, Community
Problem: IAM groups, collaboration teams, social communities, and authz member
relations use overlapping labels.
Source evidence:
- LDAP/SCIM Group = entry with member references (`ldap`, `scim` notes)
- ActivityPub Group actor = collective social actor (`activitypub-actors-followers.md`)
- Zanzibar `group#member@user` = authz tuple (`zanzibar-rebac.md`)
- Cerbos derived role from group attribute (`cerbos-abac-derived-roles.md`)
- Schema.org Organization subtypes include SportsTeam (`schema-org` note)
Canonical stance:
- Group = named collection with membership
- Role = capability bundle or relationship label
- Team = collaboration group or org unit
- Community = participation-oriented collective actor
```
### Conflict: Member, Follower, Affiliate
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 120133; SHA-256 `59c522c4fa0602246033c3d4bf91b91d718119bc116ad60df9f9c7fda616cefc`.
Historical wording; this is not a current model definition.
```text
## Conflict: Member, Follower, Affiliate
Problem: membership, following, affiliation, and authz member relations hide
distinct semantics behind `member`.
Source evidence:
- ActivityPub Follow ≠ membership (`activitypub-actors-followers.md`)
- Schema.org affiliation looser than memberOf (`schema-org-person-organization-membership.md`)
- OpenFGA organization#member = authz projection (`openfga-modeling.md`)
- FOAF member = group membership; knows = acquaintance (`foaf` note)
Canonical stance: use typed relationships with scope and evidence.
```
### Conflict: Profile And Persona
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 134149; SHA-256 `7e0380ec397e1c991a40391d366913e7087b4a3f45d416b92c068e34a71450b8`.
Historical wording; this is not a current model definition.
```text
## Conflict: Profile And Persona
Problem: profiles are account records, RDF documents, public pages, or VC subjects.
Source evidence:
- WebID profile document = RDF at URI (`webid-solid-profile.md`)
- Kratos traits often called profile informally (`ory-kratos-keto.md`)
- ActivityPub actor profile = public actor representation
- Persona for pairwise/pseudonymous scoped presentation (OIDC, GDPR notes)
Canonical stance:
- Profile = presentation surface in scope
- Persona = deliberate contextual presentation with privacy boundaries
```
### Conflict: Synonymity, Linking, Matching, Merge
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 163177; SHA-256 `a714d30d2c1bedfcfe3020fa277c5a6226ec408eebd65efc33aadcba9b825ddf`.
Historical wording; this is not a current model definition.
```text
## Conflict: Synonymity, Linking, Matching, Merge
Problem: systems collapse probabilistic matches, verified links, and destructive
merges into one feature.
Source evidence:
- Probabilistic matching → weak assertion (`deterministic-vs-probabilistic-matching.md`)
- OIDC iss+sub binding → strong scoped assertion (`oidc`, `synonymity-assertions` notes)
- Schema.org sameAs = weak web equivalence (`schema-org` note)
- GDPR cross-linking raises identifiability risk (`gdpr-pseudonymization.md`)
- MDM golden record merge = downstream anti-pattern (`deterministic` note)
Canonical stance: synonymity is scoped, evidenced, revocable assertion.
```
### Conflict: Issuer
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 191203; SHA-256 `e7ca901947a8931fb1c427fa217f22bac361c15aa6c57da67580d799676980a7`.
Historical wording; this is not a current model definition.
```text
## Conflict: Issuer
Problem: issuer means OIDC OP, VC issuer, SAML IdP, or CSP.
Source evidence:
- OIDC iss claim defines subject namespace (`oidc-core-subject-identifiers.md`)
- VC issuer signs credential (`vc-data-model-2.md`)
- NIST CSP performs proofing (`nist-800-63-4.md`)
Canonical stance: Issuer = Scope authority + Trust Relationship; specify protocol
role when mapping.
```
### Conflict: Customer Account
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 204222; SHA-256 `f88abdae039caa5135f7acfb7545747a141fe84703b23f45c918c209d1b73654`.
Historical wording; this is not a current model definition.
```text
## Conflict: Customer Account
Problem: `customer account` collapses login account, B2B subscriber organization,
Stripe billing customer, and CRM account into one product noun.
Source evidence:
- Auth0 uses Subscriber for tenant holder, not customer account (`b2b-saas-subscriber-tenancy.md`)
- Stytch: organization is the customer (`b2b-saas-subscriber-tenancy.md`)
- Stripe Customer is billing object with subscriptions, not login (`stripe-customer-billing.md`)
- ZITADEL/Keycloak org-as-tenant has no Customer Account type (`zitadel`, `keycloak` notes)
Canonical stance: **reject Customer Account** as canonical term. Resolve by layer:
- login/access → Account;
- subscribing company → Organization + Customer role + Tenant;
- billing/CRM → Commercial Record;
- vendor↔customer link → Commercial Relationship.
```
### actor
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 1717; SHA-256 `6ceb7d60a09ca5471237860930d88dd8367e7bbda1cd4605eee58d89f9a5bd72`.
Historical wording; this is not a current model definition.
```text
| actor | Actor | ActivityPub, FOAF, Cedar, proposal | Participation root. ActivityPub actor is server-hosted; FOAF Agent includes persons. |
```
### natural person
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 1818; SHA-256 `973e4a0177d5241ce7090eb6e36e29cb8036bd3b23c3c4b793bfdc476ccbbb39`.
Historical wording; this is not a current model definition.
```text
| natural person | Natural Person | FOAF, Schema.org, NIST, GDPR | Human being; FOAF Person and Schema.org Person align strongly. |
```
### account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2020; SHA-256 `1901d71fbc43e06b5134161854710bf0f653141bc626bf67d95d4cfd3db0e10f`.
Historical wording; this is not a current model definition.
```text
| account | Account | SCIM, LDAP posixAccount, FOAF OnlineAccount, Keycloak | Operational access record in a scope. FOAF separates account from person explicitly. |
```
### subject
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2525; SHA-256 `904b2af8c84d271ad315098c387b00d51eef6463d3d4343c16469844f65f9cd5`.
Historical wording; this is not a current model definition.
```text
| subject | Authenticated Subject | OIDC, SAML, SSF events | Protocol/security view after issuer identification. Not Actor or Principal. |
```
### end-user
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2727; SHA-256 `74c3cc32b9d4ce44cf2b61a4673ea73073be69d31900f302937110ab74c43c4c`.
Historical wording; this is not a current model definition.
```text
| end-user | Natural Person (inferred) | OIDC | OIDC names the human implicitly; does not model as entity. |
```
### agent
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3030; SHA-256 `30a826d21d04b01e4de5648711bdd38e1e106bbb25d2ab2f1f611912d0f7b3b1`.
Historical wording; this is not a current model definition.
```text
| agent | Actor or Artificial Agent | FOAF, ActivityPub, WebID | FOAF Agent includes humans; ActivityPub Service = Artificial Agent. |
```
### bot
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3131; SHA-256 `827962be82a98f1c17ffb62c4f4cd943a66a753d67e5cca0fc8ef77756e8ffad`.
Historical wording; this is not a current model definition.
```text
| bot | Artificial Agent | ActivityPub Service, apps | Automated actor; may use Service Account. |
```
### organization
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3434; SHA-256 `b3deaa2097bfa8f94206f0d599bf434e202e1a3a72ff5ff0ac556ab9ad00efe3`.
Historical wording; this is not a current model definition.
```text
| organization | Organization | Schema.org, Keycloak Orgs, ZITADEL, SCIM ext | Collective actor. SCIM `organization` attribute is not an Organization actor. |
```
### legal entity
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3535; SHA-256 `da327d376e38707f55e5a1fbcdd4dee8f76bfc6cb4ec2e8468a90079f2ca1a5a`.
Historical wording; this is not a current model definition.
```text
| legal entity | Legal Entity | business, compliance | Organization recognized under law; separate from tenant. |
```
### customer
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3636; SHA-256 `3e7b01c8abe4d58617b4902063eb4f5f14e7cac5da49a8ff778c33f9bc4716a9`.
Historical wording; this is not a current model definition.
```text
| customer | Customer (relationship role) | SaaS, vendor models | B2B subscriber org → Organization + Customer role + Tenant. Not Stripe Customer. |
```
### vendor
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3737; SHA-256 `68a088043e8cb63172b4c57325022708379566e12a9cf605400179c16a4f46b7`.
Historical wording; this is not a current model definition.
```text
| vendor | Vendor (relationship role) | SaaS, multi-vendor | Provider role; not realm or tenant. |
```
### subscriber
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3838; SHA-256 `3194121265ab0f7be752878e2168006b71c72b9f200f1e5e02aac4f078de5bf4`.
Historical wording; this is not a current model definition.
```text
| subscriber | Organization + Customer role | Auth0 B2B SaaS | Convenience label only; not canonical. |
```
### pan / cvv / chd
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 4242; SHA-256 `84eacf96d9ff1a172086a00c1ecf31e94f5b594ee4dce3559e8ccd2525ab6b9c`.
Historical wording; this is not a current model definition.
```text
| pan / cvv / chd | Out of canon | PCI DSS | Downstream PCI vault only. |
```
### beneficial owner
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5252; SHA-256 `5c1d61373f92b79b054fe3d605a5d8171b2af91ebc9b3636f7b07015b3ce85f0`.
Historical wording; this is not a current model definition.
```text
| beneficial owner | Beneficial Owner + Beneficial Ownership Relationship | KYC/AML, FinCEN CDD, FATF R24 | Natural person behind legal entity customer; dedicated relationship type with ownership/control prongs. |
```
### beneficial ownership
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5353; SHA-256 `8520301fabb9a30b9055f47f6b8b957636038fe4f6ec4a34761cfd233780d40a`.
Historical wording; this is not a current model definition.
```text
| beneficial ownership | Beneficial Ownership Relationship | FinCEN CDD, BOI, Open Ownership | Regulated Natural Person → Organization/Legal Entity linkage; not Ownership subtype. |
```
### iso 6523 / icd
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5959; SHA-256 `03da1b9755c903ab6c7d865a98c27223f9d7477629602c635394956f3404dc31`.
Historical wording; this is not a current model definition.
```text
| iso 6523 / icd | Registry Identifier scheme | ISO/IEC 6523, PEPPOL | ICD + organization identifier encoding. |
```
### legal person
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 6060; SHA-256 `5138cf572034760b21f365bcae5e73346acf6d88c2f65cee751d6b02454d9766`.
Historical wording; this is not a current model definition.
```text
| legal person | Legal Person | eIDAS, civil law, agency | Natural or juridical person under law. |
```
### control_basis
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7171; SHA-256 `7923f00e6a10cdd05fd7b3bc8a5013fc837a36bd1f984fb84fc8f4447e147a7c`.
Historical wording; this is not a current model definition.
```text
| control_basis | Beneficial Ownership Relationship metadata | FinCEN CDD, EU AMLD | Settled role enum (chief_executive, managing_member, …). |
```
### fincen id
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7373; SHA-256 `f0bfb45e5363934041ff910a44cd0d69b578679f9c22719365fb0319b314fb78`.
Historical wording; this is not a current model definition.
```text
| fincen id | Registry Identifier (government_registry) | BOI | Natural person government registry ID. |
```
### person account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7474; SHA-256 `b75fc9b5ca6ef2146e019e342f8565d138eeefccc4b2ee845f010c835d5567eb`.
Historical wording; this is not a current model definition.
```text
| person account | Natural Person + Commercial Record | Salesforce B2C | Adapter projection_mode person_account_combined only. |
```
### crm account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7979; SHA-256 `9b1dcdfbe61b780895d51b439da2dffc0df0df7cc4dfb4d57de7dd3f8eb30d0e`.
Historical wording; this is not a current model definition.
```text
| crm account | Commercial Record | Salesforce | Company/household commercial record. |
```
### community
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8888; SHA-256 `0511a75af9b3a29cc2519527193f01cf70d04c0b0e04546127b14a7bd2ec5c8a`.
Historical wording; this is not a current model definition.
```text
| community | Community | ActivityPub Group, proposal | Participation-oriented collective. ActivityPub Group may be Community or Group. |
```
### family
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8989; SHA-256 `b1494107b59c6ed89546a86eeb073414ee575a2376f3c695ecb23b5c2668e32d`.
Historical wording; this is not a current model definition.
```text
| family | Family or Household | proposal, GDPR-sensitive | Guardian/dependent semantics; privacy-sensitive. |
```
### household
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9090; SHA-256 `0719bdf791feaaf5a70b1990b2ea38f730312c1addbbdd6562ddb0b7abbb75ed`.
Historical wording; this is not a current model definition.
```text
| household | Family or Household | family accounts | Co-residence unit; may differ from legal family. |
```
### group
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9191; SHA-256 `46830fccca86caeda6623d000dc25708edfbc3fbce2be1d4746a7b4d3482dd43`.
Historical wording; this is not a current model definition.
```text
| group | Group | LDAP, SCIM, FOAF, ActivityPub, Cedar | Named collection. LDAP/SCIM group ≠ social community without context. |
```
### team
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9292; SHA-256 `ad2667febbf25827e07ad34d4f413f4165078eda36f90fccd92361b88bc56737`.
Historical wording; this is not a current model definition.
```text
| team | Group or Organization Unit | Schema.org, collaboration | Collaboration unit; may be org sub-unit. |
```
### role
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9393; SHA-256 `bf4b3c078725e3a9b4c661c358df673204d21865de9386223c00682de7a76d2a`.
Historical wording; this is not a current model definition.
```text
| role | Role | Keycloak, ZITADEL, Cedar, Cerbos, Schema.org OrganizationRole | Capability bundle or relationship label. Cerbos derived role may hide Ownership. |
```
### grant
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9494; SHA-256 `ca2c9b2882bd176716d5f40b570f7d142e820881529353bdd9829ca2fff5acfd`.
Historical wording; this is not a current model definition.
```text
| grant | Role assignment | ZITADEL | Project role assignment; map to Delegation-like relationship. |
```
### member
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9595; SHA-256 `a6600f7dd9604883a0c366467ad89a90ceee68aefbe6aca09067ada754baae23`.
Historical wording; this is not a current model definition.
```text
| member | Membership Relationship | SCIM, LDAP, FOAF, Schema.org, Zanzibar | Relationship edge, not a noun for the participant. |
```
### affiliation
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9696; SHA-256 `06170379083ad57eb7ec1dee172d3f2e370140f32c1e8b3ccf5a700c3fffdb66`.
Historical wording; this is not a current model definition.
```text
| affiliation | Affiliation Relationship | Schema.org, FOAF knows | Looser than membership. FOAF knows is weak social affiliation. |
```
### follower
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9797; SHA-256 `62256899610e66f10a97b6f7011d52ff02ce79f6d4060c0d403bc8a520f3e6ff`.
Historical wording; this is not a current model definition.
```text
| follower | Following Relationship | ActivityPub | Directed social subscription; not membership or authz. |
```
### policy
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 117117; SHA-256 `13bcf330fb1989abf5ba4d7c673d2c3a646480236f81792abadb74afa660b983`.
Historical wording; this is not a current model definition.
```text
| policy | Authorization Projection | Cedar, Cerbos | Rule artifact; downstream of canon model. |
```
### subscriber
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 119119; SHA-256 `778a574609c40787ae9fec045e791faafd3d39b49fd187b3c10bc6dad0133e4c`.
Historical wording; this is not a current model definition.
```text
| subscriber | Account / Identity Record | NIST | Enrolled party at CSP; not synonymous with Natural Person until IAL binding. |
```
### holder
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 128128; SHA-256 `1e57bb144bb8a072a4180be14a8a91f8126c4f958397a8fd62e12c63db8806b6`.
Historical wording; this is not a current model definition.
```text
| holder | Actor (custody role) | VC, OpenID4VC | Party possessing VC; may differ from subject. |
```
### verifier
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 129129; SHA-256 `d37d10d4b1113114369aa128754a243e56f9ee71e5f95d5d9f966d75fe94088b`.
Historical wording; this is not a current model definition.
```text
| verifier | Scope (evaluation role) | VC, OpenID4VC | Validates presentations. |
```
### webid
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 131131; SHA-256 `e08c6ed7932919efd4c8f8ae55161be7a02e983d667cf3359fcff0affde44a1b`.
Historical wording; this is not a current model definition.
```text
| webid | Identifier | WebID/Solid | HTTP URI identifying agent with dereferenceable profile. |
```
### data subject
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 132132; SHA-256 `2aae43d6df259e4678d0a2d27fcf4efd546ecd99201d1a3e573cef845e78a822`.
Historical wording; this is not a current model definition.
```text
| data subject | Natural Person | GDPR | Identifiable natural person for privacy regulation. |
```
### controller
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 134134; SHA-256 `161324c016daae2806cd837b82beceffd4ea2b3ce981683b5ed39f58132b19e8`.
Historical wording; this is not a current model definition.
```text
| controller | Organization (legal role) | GDPR | Downstream legal role; not canonical identity root. |
```
### derived role
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 137137; SHA-256 `cbfaa9a627d2d32e194e4301e908fd193eb67c788ac3afad98079ce92e898fce`.
Historical wording; this is not a current model definition.
```text
| derived role | Role (computed) | Cerbos | Role from attributes; should trace to Relationship when possible. |
```
### contextual tuple
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 138138; SHA-256 `5b1c5f8c2795fc54d61f319bd4c6238538588fa4026e779d0ed615e998133218`.
Historical wording; this is not a current model definition.
```text
| contextual tuple | Delegation context | OpenFGA | Ephemeral authz fact at check time. |
```
### organizationrole
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 140140; SHA-256 `ca2eda7a31f21b54ff220456146ef06584ab01844034832e519a9c9c0febf576`.
Historical wording; this is not a current model definition.
```text
| organizationrole | Role + Membership | Schema.org | Temporal role with start/end dates. |
```