Give every user unique credentials, keep ordinary and privileged accounts apart, and when employees or other users leave, recover their security devices and disable their accounts.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.