If an IT service provider is used, the system administrator keeps an additional list of all accounts with administrative permission used by the provider, showing the system administered and the login names.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.