Apply role based access control across the orchestrator using least privilege. Restrict cluster admin privileges to a small named group and prefer namespace scoped roles for development teams.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.