Despite rule 4.6, a data holder must not disclose data about an account where the request was made for a secondary user and the account holder has indicated on its dashboard that it no longer approves disclosure to that accredited person for that secondary user, or where another rule (for example the joint account rules in subrules 4A.10(5) and (6)) forbids disclosure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.