Access to records is managed through authorised processes. Systems support granting and restricting access for agents individually or in aggregate using current, authorised access and permissions rules, and may deliver records, metadata or redacted versions. Application of rules is recorded as process metadata, including changes to rules with the authority and date, and instances of access may be logged where requirements and risk call for it.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.