Authenticate humans and services accessing the orchestrator API using strong identity providers. Disable static token bootstrap accounts once cluster setup is complete and ensure all administrative actions tie back to a named identity.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.