Determines whether authorizations granted are limited to what each user needs for assigned duties, and whether privilege grants are reviewed rather than left to accumulate.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.