info-tech-canon/infospace/assimilation/canon-federation/views/itc-ident.md
tegwick 372f671eef
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Distribute frozen federation corpus by concept destination
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b
2026-09-06 00:44:37 +02:00

1439 lines
62 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# itc-ident provenance reading index
Historical input only. Current canon and ADR-006 override superseded assertions.
- [research/CorpusIndex.md](../source/research/CorpusIndex.md) — d110cd1f6653.
- [research/README.md](../source/research/README.md) — 1ab93b1176ac.
- [research/ResearchSeed.md](../source/research/ResearchSeed.md) — 1e432ff04d17.
- [research/authentication-federation/nist-800-63-4.md](../source/research/authentication-federation/nist-800-63-4.md) — 8697b739399c.
- [research/authentication-federation/oidc-core-subject-identifiers.md](../source/research/authentication-federation/oidc-core-subject-identifiers.md) — e1a0bf8a2754.
- [research/authentication-federation/saml-nameid-federation.md](../source/research/authentication-federation/saml-nameid-federation.md) — 394457cf75d2.
- [research/authentication-federation/shared-signals-caep-risc.md](../source/research/authentication-federation/shared-signals-caep-risc.md) — 7303fd449a83.
- [research/authorization-relationships/cedar-principal-action-resource-context.md](../source/research/authorization-relationships/cedar-principal-action-resource-context.md) — 1932a8632dd3.
- [research/authorization-relationships/cerbos-abac-derived-roles.md](../source/research/authorization-relationships/cerbos-abac-derived-roles.md) — c35f15042d45.
- [research/authorization-relationships/openfga-modeling.md](../source/research/authorization-relationships/openfga-modeling.md) — e2d03ddfa7be.
- [research/authorization-relationships/zanzibar-rebac.md](../source/research/authorization-relationships/zanzibar-rebac.md) — 1f736195ab4b.
- [research/commercial-identity/beneficial-ownership-kyc-boi.md](../source/research/commercial-identity/beneficial-ownership-kyc-boi.md) — 602aad062291.
- [research/commercial-identity/commercial-identity-nuance-settlement.md](../source/research/commercial-identity/commercial-identity-nuance-settlement.md) — cabb54601ee7.
- [research/commercial-identity/commercial-identity-synthesis.md](../source/research/commercial-identity/commercial-identity-synthesis.md) — ac70ecdb2046.
- [research/commercial-identity/commercial-trust-binding-theory.md](../source/research/commercial-identity/commercial-trust-binding-theory.md) — fc7be6f0641b.
- [research/commercial-identity/crm-pipeline-commitment-threshold.md](../source/research/commercial-identity/crm-pipeline-commitment-threshold.md) — 459828097e09.
- [research/commercial-identity/duns-commercial-credit-identity.md](../source/research/commercial-identity/duns-commercial-credit-identity.md) — b33b789b047f.
- [research/commercial-identity/eidas-eudi-legal-person-wallet.md](../source/research/commercial-identity/eidas-eudi-legal-person-wallet.md) — be8b05990cd0.
- [research/commercial-identity/kyc-aml-commercial-identity-binding.md](../source/research/commercial-identity/kyc-aml-commercial-identity-binding.md) — 5d3f63465cd7.
- [research/commercial-identity/legal-person-agency-contract.md](../source/research/commercial-identity/legal-person-agency-contract.md) — c3110cc62b49.
- [research/commercial-identity/lei-gleif-legal-entity-identifier.md](../source/research/commercial-identity/lei-gleif-legal-entity-identifier.md) — ef2ba7156f6d.
- [research/commercial-identity/payment-credential-pci-boundary.md](../source/research/commercial-identity/payment-credential-pci-boundary.md) — bcacaee7090c.
- [research/commercial-identity/registry-identifier-subtypes.md](../source/research/commercial-identity/registry-identifier-subtypes.md) — 1a621787a869.
- [research/commercial-identity/reputation-assurance-gradient.md](../source/research/commercial-identity/reputation-assurance-gradient.md) — 0c992d05657d.
- [research/commercial-identity/salesforce-crm-commercial-record.md](../source/research/commercial-identity/salesforce-crm-commercial-record.md) — 52bf8c8dbbd7.
- [research/commercial-subscription/b2b-saas-subscriber-tenancy.md](../source/research/commercial-subscription/b2b-saas-subscriber-tenancy.md) — 133bf4325a7c.
- [research/commercial-subscription/stripe-customer-billing.md](../source/research/commercial-subscription/stripe-customer-billing.md) — bb5c8fe3cab7.
- [research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md](../source/research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md) — 12585f844728.
- [research/entity-resolution-privacy/gdpr-pseudonymization.md](../source/research/entity-resolution-privacy/gdpr-pseudonymization.md) — de2bfcf7f52b.
- [research/entity-resolution-privacy/synonymity-assertions.md](../source/research/entity-resolution-privacy/synonymity-assertions.md) — 6ba40ec37221.
- [research/identity-provisioning/keycloak-organizations.md](../source/research/identity-provisioning/keycloak-organizations.md) — 09c43cdc9ecf.
- [research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md](../source/research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md) — c3f3323a3f25.
- [research/identity-provisioning/ory-kratos-keto.md](../source/research/identity-provisioning/ory-kratos-keto.md) — 5cd12c38f8d3.
- [research/identity-provisioning/scim-rfc7643-rfc7644.md](../source/research/identity-provisioning/scim-rfc7643-rfc7644.md) — c5c03952ac2f.
- [research/identity-provisioning/zitadel-organizations-projects.md](../source/research/identity-provisioning/zitadel-organizations-projects.md) — f4b1b6f4cce3.
- [research/social-community-graphs/activitypub-actors-followers.md](../source/research/social-community-graphs/activitypub-actors-followers.md) — 8b28bfc385d1.
- [research/social-community-graphs/foaf-agent-person-group-onlineaccount.md](../source/research/social-community-graphs/foaf-agent-person-group-onlineaccount.md) — 4131e7685da5.
- [research/social-community-graphs/schema-org-person-organization-membership.md](../source/research/social-community-graphs/schema-org-person-organization-membership.md) — bc274f7cf1ff.
- [research/social-community-graphs/webid-solid-profile.md](../source/research/social-community-graphs/webid-solid-profile.md) — abf0c62e23b0.
- [research/verifiable-claims/did-core.md](../source/research/verifiable-claims/did-core.md) — cbe5fd46e093.
- [research/verifiable-claims/openid4vc.md](../source/research/verifiable-claims/openid4vc.md) — e6fcc0612146.
- [research/verifiable-claims/vc-data-model-2.md](../source/research/verifiable-claims/vc-data-model-2.md) — dae7bc679c6c.
- [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) — 400641667064.
- [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) — 06c8134a399a.
- [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) — 5d22816b0bfe.
## Shared terminology and scenario fragments
### S01. Single Person With One Local Account
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 1324; SHA-256 `0040dd866009ad1199e89f89267e3aab86894859f6ae6d07f393e4f0b8cdb6f5`.
Historical wording; this is not a current model definition.
```text
## S01. Single Person With One Local Account
Expected representation: one Natural Person, one Account in an application
Scope, one local Identifier, one Profile, and one Membership or access
relationship if the account belongs to a group.
Checks:
- The person is not identical to the account.
- The profile is not the credential.
- Authorization can project the account or subject into a Principal.
```
### S02. Person With Multiple Accounts Across Scopes
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 2535; SHA-256 `69cabdc1680936fffd25378d9a1fcaa129c258eeca03663a3c9e9718def6fd59`.
Historical wording; this is not a current model definition.
```text
## S02. Person With Multiple Accounts Across Scopes
Expected representation: one Natural Person, multiple Accounts, one Account
per Scope, and optional Synonymity Assertions linking account records.
Checks:
- Each account keeps its source and lifecycle state.
- Linking accounts does not merge them destructively.
- Different scopes can use different identifiers.
```
### S03. Enterprise With Sub-Organizations
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 3647; SHA-256 `76282210f7df6bf26635ede205ed08215908eb82f8c84d411178bc01516a3f4d`.
Historical wording; this is not a current model definition.
```text
## S03. Enterprise With Sub-Organizations
Expected representation: Organization actors linked by structural
relationships, plus Accounts and Membership relationships scoped to relevant
systems.
Checks:
- Sub-organization is not automatically a tenant.
- Legal entity status is modeled separately.
- Membership and administration relationships are explicit.
```
### S04. Vendor Tenant Serving Customer Tenants
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 4859; SHA-256 `f674aa6466c45664d941359e2016a5f43a9ef58f58f1299f1ecb39003ef9a0c3`.
Historical wording; this is not a current model definition.
```text
## S04. Vendor Tenant Serving Customer Tenants
Expected representation: Vendor and Customer relationship roles between
Organization actors; Tenant scopes for platform isolation; optional
Administration relationships for delegated support.
Checks:
- Customer is not collapsed into Tenant.
- Vendor is not collapsed into Realm.
- Cross-tenant administration is scoped and evidenced.
```
### S05. Customer Organization With Delegated Administrators
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 6070; SHA-256 `40271bc925011808c60854faf342853ed48ff737afc7885921b62696b02c69d3`.
Historical wording; this is not a current model definition.
```text
## S05. Customer Organization With Delegated Administrators
Expected representation: Organization actor, Tenant scope, administrator
Accounts, Delegation and Administration relationships.
Checks:
- Admin rights are relationships, not just group names.
- Delegation has source, target, scope, and lifecycle state.
- Authorization projection can consume the relationship separately.
```
### S06. Family With Guardian And Dependent Accounts
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 7182; SHA-256 `a3f0705f7168974632f544891e08403fdcdaa2b205f40ae899bc0483af445106`.
Historical wording; this is not a current model definition.
```text
## S06. Family With Guardian And Dependent Accounts
Expected representation: Family or Household collective actor, Natural Person
actors, guardian/dependent relationships, child Accounts, and privacy
constraints.
Checks:
- Guardian relationship is not generic membership.
- Household and legal family can differ.
- Privacy-sensitive links can be scoped.
```
### S07. Spontaneous Interest Group
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 8393; SHA-256 `b4d3ed3df96d57dfc9defcb0395c134e500c79375972ccb978c2abfb64da7247`.
Historical wording; this is not a current model definition.
```text
## S07. Spontaneous Interest Group
Expected representation: Community or Group collective actor, Membership
relationships, optional moderator Administration relationships.
Checks:
- Informal group does not need legal entity or tenant semantics.
- Moderation is not the same as membership.
- Group identity can exist without strong real-world identity proofing.
```
### S08. Community With Members, Moderators, And Followers
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 94105; SHA-256 `83de4820c3662f015970f7360ceb1278bca3fa8bf63037826316d63643e580ae`.
Historical wording; this is not a current model definition.
```text
## S08. Community With Members, Moderators, And Followers
Expected representation: Community actor; Membership relationships for
members; Administration or moderation relationships for moderators; Following
relationships for followers.
Checks:
- Follower is not a member unless the source says so.
- Moderator authority is explicit and scoped.
- Public profile can differ from account.
```
### S09. Social Media Follower Graph
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 106116; SHA-256 `fd342efc3924c194784c48d937333426addcac7e8404a1834881e284937777b3`.
Historical wording; this is not a current model definition.
```text
## S09. Social Media Follower Graph
Expected representation: Actor or Persona profiles connected by Following
relationships in a social Scope.
Checks:
- Following is directed.
- Following does not imply affiliation, membership, trust, or authorization.
- Pseudonymous profiles can remain scoped.
```
### S10. Bot Or Service Account Acting For An Organization
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 117127; SHA-256 `b7671fae9cd9c0c2070588558e72fc34e6a40a449b088738761253df23955228`.
Historical wording; this is not a current model definition.
```text
## S10. Bot Or Service Account Acting For An Organization
Expected representation: Artificial Agent actor, Service Account, Organization
actor, Representation or Delegation relationship, and Credential records.
Checks:
- Bot is not a natural person.
- Service account has an owner or responsible actor.
- Delegated authority has bounded scope and lifecycle.
```
### S11. AI Agent Acting Under Delegated Authority
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 128139; SHA-256 `c26e3ad239e21e320a65dcee09b95260db582d26ff08c3b7cf537577c9501275`.
Historical wording; this is not a current model definition.
```text
## S11. AI Agent Acting Under Delegated Authority
Expected representation: Artificial Agent actor, Account or Service Account,
Delegation relationship from a Natural Person or Organization, and audit or
evidence references for actions.
Checks:
- Delegation identifies who granted authority.
- Agent actions can be attributed without treating the agent as the person.
- Authorization projection can include delegated context.
```
### S12. Weak Identity Match From Imported Data
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 140150; SHA-256 `b5f26ea04922d59bfe1c7dd240a2348e4afc6cc45a257ea5dfbb733e614649d5`.
Historical wording; this is not a current model definition.
```text
## S12. Weak Identity Match From Imported Data
Expected representation: source Identity Records linked by a weak Synonymity
Assertion with method, evidence, confidence, scope, and lifecycle state.
Checks:
- Weak match does not merge accounts.
- Consumers can reject or quarantine weak links.
- Evidence source remains visible.
```
### S13. Strong Account Link After Explicit Verification
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 151161; SHA-256 `4d4ec21f4e4a70bd1095e0baa7691c39497f970fab42a073683a0200c5ee5949`.
Historical wording; this is not a current model definition.
```text
## S13. Strong Account Link After Explicit Verification
Expected representation: Accounts linked by a strong Synonymity Assertion or
Account Link relationship, with verification evidence and revocation path.
Checks:
- Strong link is still scoped.
- Verification method is recorded.
- Revocation or unlinking is possible.
```
### S14. Pseudonymous Profile Linked Only Within A Restricted Scope
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 162172; SHA-256 `01618fb5fc15400461ceb46402bc5c908fdd3555c3e2aa04adb964faf466bab1`.
Historical wording; this is not a current model definition.
```text
## S14. Pseudonymous Profile Linked Only Within A Restricted Scope
Expected representation: Persona or Profile with Scoped Identifier and
privacy-limited Synonymity Assertion visible only inside an allowed Scope.
Checks:
- Public consumers cannot infer the hidden link.
- The pseudonym can have relationships independent of legal identity.
- Scope boundaries are explicit.
```
### S15. Organization Represented By A Legal Entity And Operational Tenants
Frozen source: [scenarios/ScenarioTests.md](../source/scenarios/ScenarioTests.md) lines 173184; SHA-256 `a809f4bae8f243f9034887ad2c16903449999ae695c2fc1c4fc089cf9b7020a0`.
Historical wording; this is not a current model definition.
```text
## S15. Organization Represented By A Legal Entity And Operational Tenants
Expected representation: Organization actor, Legal Entity specialization or
relationship, one or more Tenant scopes, and Representation relationships for
authorized persons or agents.
Checks:
- Legal entity and tenant are separate model elements.
- Multiple tenants can relate to one organization.
- Representation authority is scoped and evidenced.
```
### Conflict: User
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 628; SHA-256 `03cc685a840d47b36bf124aa8c1465216dfcb1c463f911dbe5e934b7fa81e3b6`.
Historical wording; this is not a current model definition.
```text
## Conflict: User
Problem: `user` can mean a person, account, login credential holder,
application profile, authorization subject, or product-facing actor.
Source evidence:
- SCIM User = provisionable Identity Record (`scim-rfc7643-rfc7644.md`)
- Keycloak/ZITADEL User = Account with credentials (`keycloak-organizations.md`,
`zitadel-organizations-projects.md`)
- OpenFGA `user:` tuple prefix = Authorization Principal id (`openfga-modeling.md`)
- OIDC End-User = implied Natural Person, not modeled (`oidc-core-subject-identifiers.md`)
Canonical stance: do not use `user` as a root concept.
Current mapping rule:
- Provisioning record (SCIM/LDAP) → Identity Record
- Login-enabled product record → Account
- Public/local display → Profile
- Access evaluation → Principal or Authenticated Subject
- Human being → Natural Person
```
### Conflict: Identity
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 2943; SHA-256 `acf3297ff3ac425a535639c97c8e9368833d0e4e78225679263bcd5ab6ecbbed`.
Historical wording; this is not a current model definition.
```text
## Conflict: Identity
Problem: `identity` can mean selfhood, a directory record, an issuer-bound
subject, a set of claims, a DID, a credential, a profile, or an account.
Source evidence:
- Kratos Identity = traits + credentials (`ory-kratos-keto.md`)
- OIDC developers conflate `sub` with "identity" (`oidc-core-subject-identifiers.md`)
- DID is identifier, not identity record (`did-core.md`)
- VC credentialSubject = claims about subject (`vc-data-model-2.md`)
Canonical stance: avoid bare `identity`. Prefer Identity Record, Identifier,
Claim, Credential, Profile, Persona, or Synonymity Assertion.
```
### Conflict: Account
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 4459; SHA-256 `5bc5a473a54d20d4cbba778d5f4508e0655cb755d118583715873b2ca81533a2`.
Historical wording; this is not a current model definition.
```text
## Conflict: Account
Problem: account can mean login account, customer billing account, social
media handle, service account, or FOAF online presence.
Source evidence:
- FOAF OnlineAccount is service presence, explicitly not Person (`foaf-agent-person-group-onlineaccount.md`)
- LDAP posixAccount is attribute bundle on person entry (`ldap-rfc4519-inetorgperson-rfc2798.md`)
- ActivityPub `acct:` URI suggests account but actor is richer (`activitypub-actors-followers.md`)
- ZITADEL machine user = Service Account (`zitadel-organizations-projects.md`)
Canonical stance: Account is operational access record in a scope. Billing
records map to Commercial Record; commercial parties use Customer/Vendor roles
and Commercial Relationship.
```
### Conflict: Subject, Principal, Actor
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 6079; SHA-256 `5f7282450703c7ab38c6d6b044bf99731c274974dd8ece1785de74bdc1365feb`.
Historical wording; this is not a current model definition.
```text
## Conflict: Subject, Principal, Actor
Problem: protocols, authorization engines, and social models overload these terms.
Source evidence:
- OIDC Subject = issuer-scoped identifier (`oidc-core-subject-identifiers.md`)
- SAML Principal = authenticated subject in assertion (`saml-nameid-federation.md`)
- Cedar Principal = typed entity in authorization request (`cedar-principal-action-resource-context.md`)
- Zanzibar/OpenFGA Subject = opaque authz participant (`zanzibar-rebac.md`)
- ActivityPub Actor = server-hosted social entity (`activitypub-actors-followers.md`)
- FOAF Agent = actionable entity, includes Person (`foaf-agent-person-group-onlineaccount.md`)
- GDPR Data Subject = natural person (`gdpr-pseudonymization.md`)
Canonical stance:
- Actor = conceptual participant
- Authenticated Subject = issuer/protocol view
- Authorization Principal = decision-engine projection
```
### Conflict: Tenant, Realm, Organization, Customer
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 8099; SHA-256 `3e920b787354989a9cce48cc7b45c915150b215b4fcdfe054b854d9cc9748191`.
Historical wording; this is not a current model definition.
```text
## Conflict: Tenant, Realm, Organization, Customer
Problem: multi-tenant products collapse isolation boundaries and commercial actors.
Source evidence:
- Keycloak Realm = hard namespace; Organization = B2B overlay (`keycloak-organizations.md`)
- ZITADEL Organization = customer boundary + org actor (`zitadel-organizations-projects.md`)
- SCIM has no tenant; org is string attribute (`scim-rfc7643-rfc7644.md`)
- Schema.org Organization = collective actor (`schema-org-person-organization-membership.md`)
Canonical stance:
- Tenant = administrative/isolation scope
- Realm = issuer/admin namespace (Scope specialization)
- Organization = collective actor
- Customer = commercial relationship role
Model relationships among them; do not synonymize.
```
### Conflict: Group, Role, Team, Community
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 100119; SHA-256 `0a8cd0ebc16563b59014cbaf3e026ae6633f24aa8f26dabe1c2bfebf70b4f3d4`.
Historical wording; this is not a current model definition.
```text
## Conflict: Group, Role, Team, Community
Problem: IAM groups, collaboration teams, social communities, and authz member
relations use overlapping labels.
Source evidence:
- LDAP/SCIM Group = entry with member references (`ldap`, `scim` notes)
- ActivityPub Group actor = collective social actor (`activitypub-actors-followers.md`)
- Zanzibar `group#member@user` = authz tuple (`zanzibar-rebac.md`)
- Cerbos derived role from group attribute (`cerbos-abac-derived-roles.md`)
- Schema.org Organization subtypes include SportsTeam (`schema-org` note)
Canonical stance:
- Group = named collection with membership
- Role = capability bundle or relationship label
- Team = collaboration group or org unit
- Community = participation-oriented collective actor
```
### Conflict: Member, Follower, Affiliate
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 120133; SHA-256 `59c522c4fa0602246033c3d4bf91b91d718119bc116ad60df9f9c7fda616cefc`.
Historical wording; this is not a current model definition.
```text
## Conflict: Member, Follower, Affiliate
Problem: membership, following, affiliation, and authz member relations hide
distinct semantics behind `member`.
Source evidence:
- ActivityPub Follow ≠ membership (`activitypub-actors-followers.md`)
- Schema.org affiliation looser than memberOf (`schema-org-person-organization-membership.md`)
- OpenFGA organization#member = authz projection (`openfga-modeling.md`)
- FOAF member = group membership; knows = acquaintance (`foaf` note)
Canonical stance: use typed relationships with scope and evidence.
```
### Conflict: Profile And Persona
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 134149; SHA-256 `7e0380ec397e1c991a40391d366913e7087b4a3f45d416b92c068e34a71450b8`.
Historical wording; this is not a current model definition.
```text
## Conflict: Profile And Persona
Problem: profiles are account records, RDF documents, public pages, or VC subjects.
Source evidence:
- WebID profile document = RDF at URI (`webid-solid-profile.md`)
- Kratos traits often called profile informally (`ory-kratos-keto.md`)
- ActivityPub actor profile = public actor representation
- Persona for pairwise/pseudonymous scoped presentation (OIDC, GDPR notes)
Canonical stance:
- Profile = presentation surface in scope
- Persona = deliberate contextual presentation with privacy boundaries
```
### Conflict: Identifier, Credential, Claim
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 150162; SHA-256 `ff9f6502a126229aa65ea20817e698285a74df128aa35ea286cf24f87462216e`.
Historical wording; this is not a current model definition.
```text
## Conflict: Identifier, Credential, Claim
Problem: tokens and documents bundle all three.
Source evidence:
- OIDC ID Token contains sub (identifier) and claims (`oidc-core-subject-identifiers.md`)
- VC = signed claims with proof (`vc-data-model-2.md`)
- DID verification method = cryptographic credential (`did-core.md`)
- SAML AttributeStatement = claims; NameID = identifier (`saml-nameid-federation.md`)
Canonical stance: identifier refers; credential proves; claim states.
```
### Conflict: Synonymity, Linking, Matching, Merge
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 163177; SHA-256 `a714d30d2c1bedfcfe3020fa277c5a6226ec408eebd65efc33aadcba9b825ddf`.
Historical wording; this is not a current model definition.
```text
## Conflict: Synonymity, Linking, Matching, Merge
Problem: systems collapse probabilistic matches, verified links, and destructive
merges into one feature.
Source evidence:
- Probabilistic matching → weak assertion (`deterministic-vs-probabilistic-matching.md`)
- OIDC iss+sub binding → strong scoped assertion (`oidc`, `synonymity-assertions` notes)
- Schema.org sameAs = weak web equivalence (`schema-org` note)
- GDPR cross-linking raises identifiability risk (`gdpr-pseudonymization.md`)
- MDM golden record merge = downstream anti-pattern (`deterministic` note)
Canonical stance: synonymity is scoped, evidenced, revocable assertion.
```
### Conflict: Credential (Auth) vs. Verifiable Credential
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 178190; SHA-256 `ba22d9bb343b383c489c3887a36dafea1c1b93cbed3d9b799727eb5f2a03ecac`.
Historical wording; this is not a current model definition.
```text
## Conflict: Credential (Auth) vs. Verifiable Credential
Problem: "credential" means password, OIDC token, or W3C VC.
Source evidence:
- NIST authenticator/credential (`nist-800-63-4.md`)
- VC Data Model verifiable credential (`vc-data-model-2.md`)
- OpenID4VC bridges OAuth credential terminology with VCs (`openid4vc.md`)
Canonical stance: use Credential with context. VC maps to Credential containing
Claims; login secrets map to Credential (authentication factor).
```
### Conflict: Issuer
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 191203; SHA-256 `e7ca901947a8931fb1c427fa217f22bac361c15aa6c57da67580d799676980a7`.
Historical wording; this is not a current model definition.
```text
## Conflict: Issuer
Problem: issuer means OIDC OP, VC issuer, SAML IdP, or CSP.
Source evidence:
- OIDC iss claim defines subject namespace (`oidc-core-subject-identifiers.md`)
- VC issuer signs credential (`vc-data-model-2.md`)
- NIST CSP performs proofing (`nist-800-63-4.md`)
Canonical stance: Issuer = Scope authority + Trust Relationship; specify protocol
role when mapping.
```
### Conflict: Customer Account
Frozen source: [terminology/TerminologyConflictMap.md](../source/terminology/TerminologyConflictMap.md) lines 204222; SHA-256 `f88abdae039caa5135f7acfb7545747a141fe84703b23f45c918c209d1b73654`.
Historical wording; this is not a current model definition.
```text
## Conflict: Customer Account
Problem: `customer account` collapses login account, B2B subscriber organization,
Stripe billing customer, and CRM account into one product noun.
Source evidence:
- Auth0 uses Subscriber for tenant holder, not customer account (`b2b-saas-subscriber-tenancy.md`)
- Stytch: organization is the customer (`b2b-saas-subscriber-tenancy.md`)
- Stripe Customer is billing object with subscriptions, not login (`stripe-customer-billing.md`)
- ZITADEL/Keycloak org-as-tenant has no Customer Account type (`zitadel`, `keycloak` notes)
Canonical stance: **reject Customer Account** as canonical term. Resolve by layer:
- login/access → Account;
- subscribing company → Organization + Customer role + Tenant;
- billing/CRM → Commercial Record;
- vendor↔customer link → Commercial Relationship.
```
### user
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 1919; SHA-256 `0a171d978928b2781f3b7b7f28485e6d6ec53e8fe7808f42629ea7375101ec3c`.
Historical wording; this is not a current model definition.
```text
| user | Convenience label only | SCIM, LDAP, Keycloak, ZITADEL, apps | Overloaded. Map by context: SCIM/LDAP User → Identity Record; Keycloak/ZITADEL User → Account. |
```
### account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2020; SHA-256 `1901d71fbc43e06b5134161854710bf0f653141bc626bf67d95d4cfd3db0e10f`.
Historical wording; this is not a current model definition.
```text
| account | Account | SCIM, LDAP posixAccount, FOAF OnlineAccount, Keycloak | Operational access record in a scope. FOAF separates account from person explicitly. |
```
### identity
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2121; SHA-256 `779546411717fd6156a3dd3a39eb0869c68d36b10b64fff51e2dc4db9031b422`.
Historical wording; this is not a current model definition.
```text
| identity | Identity Record or Claim | Kratos, OIDC, DID, VC, apps | Kratos Identity = traits + credentials. Avoid bare `identity` as root noun. |
```
### identifier
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2222; SHA-256 `53e9132ea78c16e691b6b0e05371a99aed178d52df6d1e48704b43a40f3193cc`.
Historical wording; this is not a current model definition.
```text
| identifier | Identifier | OIDC sub, SAML NameID, LDAP DN, DID, WebID | Value referring within or across scopes. See Scoped Identifier when correlation is limited. |
```
### scoped identifier
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2323; SHA-256 `e4d333b9c4c275397cbeccd5e0b2eed27b457dff23cca482b42a086885cd2578`.
Historical wording; this is not a current model definition.
```text
| scoped identifier | Scoped Identifier | OIDC pairwise, SAML transient, pseudonyms | Meaning limited to RP, sector, tenant, or session. |
```
### credential
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2424; SHA-256 `c9d2a6c53d2e11f93234cc4fffde742aa82990efc2cb6b83024b929616030248`.
Historical wording; this is not a current model definition.
```text
| credential | Credential | NIST, Kratos, OIDC token, VC, DID keys | Proof material. Distinguish VC (claim container) from password/WebAuthn. |
```
### principal
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2626; SHA-256 `3ab8b5d536f3e1da3f172f95431751a51786291480592b7e2e784338466657ba`.
Historical wording; this is not a current model definition.
```text
| principal | Authorization Principal | Cedar, Cerbos, Zanzibar, OpenFGA | Decision-engine participant. OpenFGA `user:` prefix is not a human user. |
```
### end-user
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2727; SHA-256 `74c3cc32b9d4ce44cf2b61a4673ea73073be69d31900f302937110ab74c43c4c`.
Historical wording; this is not a current model definition.
```text
| end-user | Natural Person (inferred) | OIDC | OIDC names the human implicitly; does not model as entity. |
```
### profile
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2828; SHA-256 `f332b51b59675a5ce79ed19eb9b6ab8d7bbe4e1d651f56099068a1596669db24`.
Historical wording; this is not a current model definition.
```text
| profile | Profile | FOAF, WebID/Solid, SCIM attrs, ActivityPub | Presentation or attribute surface. Solid profile is user-controlled data. |
```
### persona
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 2929; SHA-256 `8815441b1d1f825051d8208b5a126c28d1b0a0cec1dc92fc6550b6a79f38eb2d`.
Historical wording; this is not a current model definition.
```text
| persona | Persona | proposal, privacy patterns | Contextual presentation; pairwise/pseudonymous profiles map here. |
```
### bot
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3131; SHA-256 `827962be82a98f1c17ffb62c4f4cd943a66a753d67e5cca0fc8ef77756e8ffad`.
Historical wording; this is not a current model definition.
```text
| bot | Artificial Agent | ActivityPub Service, apps | Automated actor; may use Service Account. |
```
### service account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3232; SHA-256 `64c7a3372e658872cc40799f62c5c3d7d9a8b319340a8134a829ee0a6f6082b0`.
Historical wording; this is not a current model definition.
```text
| service account | Service Account | Keycloak, ZITADEL machine user, Kratos | Non-human login or API identity. ZITADEL machine user, Kratos service patterns. |
```
### machine user
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3333; SHA-256 `5012066796bdd788383852ec7bc34a06a2fa82433dac3afbeca5f625f8b8df13`.
Historical wording; this is not a current model definition.
```text
| machine user | Service Account | ZITADEL | Product term for non-human org identity. |
```
### legal entity
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3535; SHA-256 `da327d376e38707f55e5a1fbcdd4dee8f76bfc6cb4ec2e8468a90079f2ca1a5a`.
Historical wording; this is not a current model definition.
```text
| legal entity | Legal Entity | business, compliance | Organization recognized under law; separate from tenant. |
```
### customer
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3636; SHA-256 `3e7b01c8abe4d58617b4902063eb4f5f14e7cac5da49a8ff778c33f9bc4716a9`.
Historical wording; this is not a current model definition.
```text
| customer | Customer (relationship role) | SaaS, vendor models | B2B subscriber org → Organization + Customer role + Tenant. Not Stripe Customer. |
```
### vendor
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3737; SHA-256 `68a088043e8cb63172b4c57325022708379566e12a9cf605400179c16a4f46b7`.
Historical wording; this is not a current model definition.
```text
| vendor | Vendor (relationship role) | SaaS, multi-vendor | Provider role; not realm or tenant. |
```
### subscriber
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3838; SHA-256 `3194121265ab0f7be752878e2168006b71c72b9f200f1e5e02aac4f078de5bf4`.
Historical wording; this is not a current model definition.
```text
| subscriber | Organization + Customer role | Auth0 B2B SaaS | Convenience label only; not canonical. |
```
### stripe customer
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 3939; SHA-256 `925da008d6dd0d1187f038d5bce0a3d6b6d52709672c0c7393f5b538eb65a389`.
Historical wording; this is not a current model definition.
```text
| stripe customer | Commercial Record | Stripe, billing | Billing object; link to Tenant via metadata. Not Account. |
```
### payment method / pm_xxx
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 4040; SHA-256 `1877175fcb5e0ce79e8d9145afd4ea37c10cbe9b03a4896568e868a2c38ae9ed`.
Historical wording; this is not a current model definition.
```text
| payment method / pm_xxx | Payment Instrument Reference | Stripe, Adyen | Tokenized provider reference; not Credential; not CHD in canon. |
```
### pan / cvv / chd
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 4242; SHA-256 `84eacf96d9ff1a172086a00c1ecf31e94f5b594ee4dce3559e8ccd2525ab6b9c`.
Historical wording; this is not a current model definition.
```text
| pan / cvv / chd | Out of canon | PCI DSS | Downstream PCI vault only. |
```
### crm account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 4747; SHA-256 `fae0815710a180822daf1af506d5fc59210049f8c5e2382e4094326b64a3e47f`.
Historical wording; this is not a current model definition.
```text
| crm account | Commercial Record | Salesforce, CRM | Commercial record; not login Account. |
```
### customer account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 4848; SHA-256 `86c081e76edc36dd60d4c7c2db34ba23506e1e5b1e174459cd68eb65b913cfa2`.
Historical wording; this is not a current model definition.
```text
| customer account | Resolve by layer | billing, IAM, CRM | Not canonical — see TerminologyConflictMap. |
```
### commercial relationship
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5050; SHA-256 `295a513939a88bc3fe49df82b43a20b0e89409b1969672a9a627fc63e6265f4c`.
Historical wording; this is not a current model definition.
```text
| commercial relationship | Commercial Relationship | vendor/customer SaaS | Vendor-to-customer typed relationship. |
```
### beneficial owner
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5252; SHA-256 `5c1d61373f92b79b054fe3d605a5d8171b2af91ebc9b3636f7b07015b3ce85f0`.
Historical wording; this is not a current model definition.
```text
| beneficial owner | Beneficial Owner + Beneficial Ownership Relationship | KYC/AML, FinCEN CDD, FATF R24 | Natural person behind legal entity customer; dedicated relationship type with ownership/control prongs. |
```
### beneficial ownership
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5353; SHA-256 `8520301fabb9a30b9055f47f6b8b957636038fe4f6ec4a34761cfd233780d40a`.
Historical wording; this is not a current model definition.
```text
| beneficial ownership | Beneficial Ownership Relationship | FinCEN CDD, BOI, Open Ownership | Regulated Natural Person → Organization/Legal Entity linkage; not Ownership subtype. |
```
### lei
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5454; SHA-256 `30a480ef227a05028bea2c34eb48bd0e892095df0f69ab496827932e67578b10`.
Historical wording; this is not a current model definition.
```text
| lei | Registry Identifier (regulatory_global) | GLEIF, ISO 17442, ICD 0199 | Legal entity identifier with annual renewal. |
```
### duns
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5555; SHA-256 `e0b1fc126792ef64cf0a52bc555df0d32fee966a8a092cfdc3a93020d4feb7d9`.
Historical wording; this is not a current model definition.
```text
| duns | Proxy Commercial Identifier | D&B, ICD 0060 | Commercial-proxy registry identifier. |
```
### uei
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5656; SHA-256 `20ba5293b13576bc0a7f5a1abde3a3eed2a056d43e34f2451196b9100e8338a3`.
Historical wording; this is not a current model definition.
```text
| uei | Registry Identifier (government_registry) | SAM.gov | US federal entity identifier. |
```
### company registration number
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5757; SHA-256 `837e7698d5f10320661deea52464e849bcfb001472056c75563aded71989c8c4`.
Historical wording; this is not a current model definition.
```text
| company registration number | Registry Identifier (government_registry) | national registers, ALEI | Authoritative incorporating-register identifier. |
```
### alei / ibrn
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5858; SHA-256 `222c1e86c484f60381795e6ba63bbbd684ce1b81eea5d2452ff3ec5a5bdf1dc3`.
Historical wording; this is not a current model definition.
```text
| alei / ibrn | Registry Identifier (government_registry) | ISO 8000-116 | Authoritative legal entity identifier from government register. |
```
### iso 6523 / icd
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 5959; SHA-256 `03da1b9755c903ab6c7d865a98c27223f9d7477629602c635394956f3404dc31`.
Historical wording; this is not a current model definition.
```text
| iso 6523 / icd | Registry Identifier scheme | ISO/IEC 6523, PEPPOL | ICD + organization identifier encoding. |
```
### control_basis
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7171; SHA-256 `7923f00e6a10cdd05fd7b3bc8a5013fc837a36bd1f984fb84fc8f4447e147a7c`.
Historical wording; this is not a current model definition.
```text
| control_basis | Beneficial Ownership Relationship metadata | FinCEN CDD, EU AMLD | Settled role enum (chief_executive, managing_member, …). |
```
### fincen id
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7373; SHA-256 `f0bfb45e5363934041ff910a44cd0d69b578679f9c22719365fb0319b314fb78`.
Historical wording; this is not a current model definition.
```text
| fincen id | Registry Identifier (government_registry) | BOI | Natural person government registry ID. |
```
### person account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7474; SHA-256 `b75fc9b5ca6ef2146e019e342f8565d138eeefccc4b2ee845f010c835d5567eb`.
Historical wording; this is not a current model definition.
```text
| person account | Natural Person + Commercial Record | Salesforce B2C | Adapter projection_mode person_account_combined only. |
```
### ncage / cage
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7575; SHA-256 `cadfb882fc19bda7c60bb8c75e0ed7e2e2b63974037ff07947a8a427d852b9b2`.
Historical wording; this is not a current model definition.
```text
| ncage / cage | Registry Identifier (industry_association) | defense procurement | Industry association authority class. |
```
### crm account
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 7979; SHA-256 `9b1dcdfbe61b780895d51b439da2dffc0df0df7cc4dfb4d57de7dd3f8eb30d0e`.
Historical wording; this is not a current model definition.
```text
| crm account | Commercial Record | Salesforce | Company/household commercial record. |
```
### fluid identity
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8080; SHA-256 `3c171e79b1f6966812977a4de526300db7dea729ac4bef4f86737575e836d54e`.
Historical wording; this is not a current model definition.
```text
| fluid identity | Persona / weak binding | theory | Low commercial stake; intentional mutability. |
```
### tenant
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8282; SHA-256 `8ea48ff21a23148aea6923f844adb270f01af86f334bd9fd2e6642e6ac35dc40`.
Historical wording; this is not a current model definition.
```text
| tenant | Tenant | ZITADEL org, SaaS, Keycloak (informal) | Administrative/isolation scope. Keycloak realm sometimes called tenant. |
```
### realm
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8383; SHA-256 `faaa0b5ee2eee0c243c2eda3a90df392858d974bfc1df02422a8df0b71276980`.
Historical wording; this is not a current model definition.
```text
| realm | Realm | Keycloak | Hard identity/admin namespace. Candidate Scope specialization. |
```
### scope
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8484; SHA-256 `05dc1d57cb500d7c30328b063db392cb4e4be19479c2596f739b474e640ec6bb`.
Historical wording; this is not a current model definition.
```text
| scope | Scope | OIDC, Cerbos, OpenFGA store, proposal | Boundary for meaning, policy, or correlation. |
```
### namespace
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8585; SHA-256 `348ff0b2f98a4a7b53947188a958999ec7779c636bb8fcca133075dabe031750`.
Historical wording; this is not a current model definition.
```text
| namespace | Scope | LDAP dc, Keto/OpenFGA, DID method | Naming or authorization partition. |
```
### instance
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8686; SHA-256 `a091b4ac6ab9f52f953832634e1f942fd000ead687ce46a57d4983fd7e79f33d`.
Historical wording; this is not a current model definition.
```text
| instance | Scope | ZITADEL | Deployment-level boundary above organizations. |
```
### project
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 8787; SHA-256 `329b17d1d24ed30b039ced9d3e3277cb23e49ea59f4c7ac7acf9ddae3e83dfc7`.
Historical wording; this is not a current model definition.
```text
| project | Application Scope | ZITADEL | Application/product container within org. |
```
### role
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9393; SHA-256 `bf4b3c078725e3a9b4c661c358df673204d21865de9386223c00682de7a76d2a`.
Historical wording; this is not a current model definition.
```text
| role | Role | Keycloak, ZITADEL, Cedar, Cerbos, Schema.org OrganizationRole | Capability bundle or relationship label. Cerbos derived role may hide Ownership. |
```
### grant
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9494; SHA-256 `ca2c9b2882bd176716d5f40b570f7d142e820881529353bdd9829ca2fff5acfd`.
Historical wording; this is not a current model definition.
```text
| grant | Role assignment | ZITADEL | Project role assignment; map to Delegation-like relationship. |
```
### member
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9595; SHA-256 `a6600f7dd9604883a0c366467ad89a90ceee68aefbe6aca09067ada754baae23`.
Historical wording; this is not a current model definition.
```text
| member | Membership Relationship | SCIM, LDAP, FOAF, Schema.org, Zanzibar | Relationship edge, not a noun for the participant. |
```
### affiliation
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9696; SHA-256 `06170379083ad57eb7ec1dee172d3f2e370140f32c1e8b3ccf5a700c3fffdb66`.
Historical wording; this is not a current model definition.
```text
| affiliation | Affiliation Relationship | Schema.org, FOAF knows | Looser than membership. FOAF knows is weak social affiliation. |
```
### follower
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9797; SHA-256 `62256899610e66f10a97b6f7011d52ff02ce79f6d4060c0d403bc8a520f3e6ff`.
Historical wording; this is not a current model definition.
```text
| follower | Following Relationship | ActivityPub | Directed social subscription; not membership or authz. |
```
### follow
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9898; SHA-256 `1c77e34bdf1206d046ef8eee40d4a94393faf67a5af97821834b12b9f9bcea81`.
Historical wording; this is not a current model definition.
```text
| follow | Following Relationship | ActivityPub | Activity establishing follower edge. |
```
### owner
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 9999; SHA-256 `78b48373de87a79fc4d67b68b30f7a16c2fbab573b24ddd44f8cfb13487e6896`.
Historical wording; this is not a current model definition.
```text
| owner | Ownership Relationship | Zanzibar, Cerbos derived | Control/responsibility. Cerbos may encode as attribute not relationship. |
```
### administrator
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 100100; SHA-256 `8325a4edc6753be9dadce60ad0fcfd5b46ad0528e0efc0ea9ad3a8d116a93f76`.
Historical wording; this is not a current model definition.
```text
| administrator | Administration Relationship | IAM, ZITADEL grants | Delegated management in scope. |
```
### delegation
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 101101; SHA-256 `538948038bf8b7c7e6c562238017e8efd2c4d2112e542bc9cb7d1d47d521df09`.
Historical wording; this is not a current model definition.
```text
| delegation | Delegation Relationship | Cedar context, agents | Bounded authority grant. Cedar context may carry delegatedBy. |
```
### representation
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 102102; SHA-256 `1a93d64d4e3f608806754d3889b9655d0083e2f5ce92db14780c8513fbfff419`.
Historical wording; this is not a current model definition.
```text
| representation | Representation Relationship | SCIM manager, DID controller | Acting on behalf of another. DID controller may differ from subject. |
```
### trust
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 103103; SHA-256 `3a652a6f5721c7c3616ea4fb93db81e7514538d1f2052eb00cd3333e881dd3c6`.
Historical wording; this is not a current model definition.
```text
| trust | Trust Relationship | federation, VC, DID | Reliance on issuer/verifier; federation metadata trust. |
```
### claim
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 104104; SHA-256 `1ce7bcc854285f598ad1927182e0821d7db9e9fb2a09cbd0d7e743549ca2b37e`.
Historical wording; this is not a current model definition.
```text
| claim | Claim | OIDC, SAML attributes, VC | Statement by issuer. SAML AttributeStatement → Claim. |
```
### assurance
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 106106; SHA-256 `130c61dcb0687328ed992999688e1f37c07958e258a96db49787d1d9fce90dad`.
Historical wording; this is not a current model definition.
```text
| assurance | Assurance Level | NIST IAL/AAL/FAL | Orthogonal identity, authentication, federation confidence. |
```
### identifier binding
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 107107; SHA-256 `384043ffa3353df53a5a4769971853cedccf232fe72d1a8044d1dd3b53cfc378`.
Historical wording; this is not a current model definition.
```text
| identifier binding | Identifier Binding | OIDC iss+sub, WebID-OIDC, SAML | Assertion that identifier refers to target in scope. |
```
### synonymity
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 108108; SHA-256 `58d9d36c18fda3e8df9a74af3c2fae1f3103a6f62df39d0b5db951ce3b6fe5e3`.
Historical wording; this is not a current model definition.
```text
| synonymity | Synonymity Assertion | entity resolution, OIDC linking, schema.org sameAs | Scoped evidenced equivalence. sameAs is weak by default. |
```
### weak match
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 109109; SHA-256 `3f35848a32547aa86fe3ec9e7e755e4fd6392d71ef3d683953df7b08a5c1dd95`.
Historical wording; this is not a current model definition.
```text
| weak match | Weak Synonymity Assertion | probabilistic matching | Probabilistic link; never destructive merge. |
```
### strong link
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 110110; SHA-256 `5f0902c8bed0e10535d0f76427677ac135a5c09b10b223aa49dbe05d8fc6c468`.
Historical wording; this is not a current model definition.
```text
| strong link | Strong Synonymity Assertion | deterministic match, verified linking | Authoritative or verified; still scoped. |
```
### same_as
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 111111; SHA-256 `9236ea638789b858a465b91a73dfb82c2f91434f04d7fe3bb0bcdfa623c6e951`.
Historical wording; this is not a current model definition.
```text
| same_as | Synonymity Assertion (strong) | synonymity model | High-confidence equivalence relation type. |
```
### probably_same_as
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 112112; SHA-256 `1ce7ba621eeb91881b9be16c1e87ce7a78a2a1dd26a0ff7da82b6d3fa04f2069`.
Historical wording; this is not a current model definition.
```text
| probably_same_as | Synonymity Assertion (weak) | probabilistic matching | Probabilistic equivalence relation type. |
```
### linked_to
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 113113; SHA-256 `33b998acec8a52176199992c4d0f5d1ca9016d586682e8fa5d18dbdd27957181`.
Historical wording; this is not a current model definition.
```text
| linked_to | Synonymity Assertion (operational) | account linking | Convenience link without semantic sameness claim. |
```
### pseudonym
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 114114; SHA-256 `01ebfceff32122591e256df20f312f68881ef3e6d4ebfc5738cdfa4cc28d3d69`.
Historical wording; this is not a current model definition.
```text
| pseudonym | Pseudonymous Identifier | GDPR, OIDC pairwise | Limits cross-scope correlation. |
```
### pairwise subject
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 115115; SHA-256 `508a529137ad7a0e7f1409063b306cad3bb1f8aa1c9c15f179c21ab657f46d33`.
Historical wording; this is not a current model definition.
```text
| pairwise subject | Scoped Identifier | OIDC | RP-specific sub preventing global correlation. |
```
### relationship tuple
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 116116; SHA-256 `3cab1bbb2dfc5afd3dcde230e104ddd95e67ccddc46fb2bbcc38f99103a55f49`.
Historical wording; this is not a current model definition.
```text
| relationship tuple | Relationship Tuple | Zanzibar, OpenFGA, Keto | Authz projection: subject#relation@object. |
```
### policy
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 117117; SHA-256 `13bcf330fb1989abf5ba4d7c673d2c3a646480236f81792abadb74afa660b983`.
Historical wording; this is not a current model definition.
```text
| policy | Authorization Projection | Cedar, Cerbos | Rule artifact; downstream of canon model. |
```
### lifecycle state
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 118118; SHA-256 `b39c636369a3c10a22a75c8c686d145f54addfd5720ae90da49321571406d6c6`.
Historical wording; this is not a current model definition.
```text
| lifecycle state | Lifecycle State | SCIM active, SSF/RISC events, VC status | Applies to records, credentials, relationships, assertions. |
```
### subscriber
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 119119; SHA-256 `778a574609c40787ae9fec045e791faafd3d39b49fd187b3c10bc6dad0133e4c`.
Historical wording; this is not a current model definition.
```text
| subscriber | Account / Identity Record | NIST | Enrolled party at CSP; not synonymous with Natural Person until IAL binding. |
```
### issuer
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 120120; SHA-256 `036456fa64e621bcbf2df81938ec5e5bce4af61c757456935846ef3c2c026282`.
Historical wording; this is not a current model definition.
```text
| issuer | Scope + Trust Relationship | OIDC iss, VC issuer, SAML IdP | Namespace authority for identifiers and claims. |
```
### relying party
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 121121; SHA-256 `36a83f3b965a6b2e71938360eb02a5ed64bd665797952d5f592b535e73cfa436`.
Historical wording; this is not a current model definition.
```text
| relying party | Scope | OIDC RP, SAML SP, NIST | Consumer of assertions; RP-local account binding. |
```
### nameid
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 122122; SHA-256 `dbe31e5c4483f1b3f8c83c7abe1239137c7da04456f601d8550035a0c308df12`.
Historical wording; this is not a current model definition.
```text
| nameid | Identifier | SAML | Format attribute determines persistence and privacy semantics. |
```
### distinguished name
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 123123; SHA-256 `ac1bda1aaeb885049b4ae754e1a507b1e872321069f4ca1a3fc3617660d90454`.
Historical wording; this is not a current model definition.
```text
| distinguished name | Identifier | LDAP | Compound locator in directory namespace. |
```
### externalid
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 124124; SHA-256 `e1872cf38aa8e72a824036d017710553cf8ea6f990ef05217c2e972e77c6a978`.
Historical wording; this is not a current model definition.
```text
| externalid | Identifier | SCIM | Client-supplied cross-system correlation key. |
```
### traits
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 125125; SHA-256 `aadb34d5ce8bc3500c5a4d49641d87b11b5da9a481b27dbe0d436d5c0e95117f`.
Historical wording; this is not a current model definition.
```text
| traits | Profile attributes | Kratos | Schema-validated identity attributes. |
```
### verification method
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 126126; SHA-256 `ade6d356c8a8d8db36f1991f72e711738d9281166feda19b6bf5a5ef341d2f10`.
Historical wording; this is not a current model definition.
```text
| verification method | Credential | DID Core | Cryptographic key in DID document. |
```
### verifiable credential
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 127127; SHA-256 `10b80fe4d8c1fd5880c5fb3f626bfff061b2fa2457d93bcaeaa9a6c5d27a69d3`.
Historical wording; this is not a current model definition.
```text
| verifiable credential | Credential + Claim | VC Data Model | Signed claim set; distinct from login credential. |
```
### verifier
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 129129; SHA-256 `d37d10d4b1113114369aa128754a243e56f9ee71e5f95d5d9f966d75fe94088b`.
Historical wording; this is not a current model definition.
```text
| verifier | Scope (evaluation role) | VC, OpenID4VC | Validates presentations. |
```
### did
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 130130; SHA-256 `4de4b5bba75e89eb1ad4dc0525dc0eeb3eb1102e26c3535c0e85c41a68a68551`.
Historical wording; this is not a current model definition.
```text
| did | Identifier | DID Core | Decentralized identifier with method-specific resolution. |
```
### webid
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 131131; SHA-256 `e08c6ed7932919efd4c8f8ae55161be7a02e983d667cf3359fcff0affde44a1b`.
Historical wording; this is not a current model definition.
```text
| webid | Identifier | WebID/Solid | HTTP URI identifying agent with dereferenceable profile. |
```
### pseudonymization
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 133133; SHA-256 `157015a6434ede26ec98e5b223c0d07e1cbf3f9e791ede4c11b8b2958bb67963`.
Historical wording; this is not a current model definition.
```text
| pseudonymization | Processing pattern | GDPR | Technique; maps to Scoped Identifier + separated re-id key. |
```
### tuple (authz)
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 135135; SHA-256 `89a5e53a0468189c92022352aac36ccf34b62a8a34b49c13241eb5fa91aa830c`.
Historical wording; this is not a current model definition.
```text
| tuple (authz) | Relationship Tuple | Zanzibar | Authorization fact, not social relationship. |
```
### derived role
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 137137; SHA-256 `cbfaa9a627d2d32e194e4301e908fd193eb67c788ac3afad98079ce92e898fce`.
Historical wording; this is not a current model definition.
```text
| derived role | Role (computed) | Cerbos | Role from attributes; should trace to Relationship when possible. |
```
### contextual tuple
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 138138; SHA-256 `5b1c5f8c2795fc54d61f319bd4c6238538588fa4026e779d0ed615e998133218`.
Historical wording; this is not a current model definition.
```text
| contextual tuple | Delegation context | OpenFGA | Ephemeral authz fact at check time. |
```
### sameas
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 139139; SHA-256 `be040500605effc4252c681b4b06d22cc0a7f37fbf622b0987690f4f8d39c86a`.
Historical wording; this is not a current model definition.
```text
| sameas | Weak Synonymity Assertion | Schema.org | Informal web equivalence; not strong link without evidence. |
```
### assurance level change
Frozen source: [terminology/TerminologyInventory.md](../source/terminology/TerminologyInventory.md) lines 141141; SHA-256 `1b1531452b8b67df5a400492a351662c05da740832cc507356df0f1414b40c2b`.
Historical wording; this is not a current model definition.
```text
| assurance level change | Assurance Level update | SSF/CAEP | Event affecting IAL/AAL/FAL metadata. |
```