The organisation implements, for defined access control policies, a reference monitor that is tamper-proof, always invoked, and small enough to be analysed and tested so its completeness can be assured. No enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.