Where an agency's public cloud instance is accessed through several identity systems subject to different security policies, that instance must be treated as a separate security domain from services whose access control is managed only by the agency's own identity system.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.