Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain but are not accessible over the internet.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.