Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain and are accessible over the internet.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.