Authentication and authorization are strict, enforced before access, and re evaluated as risk signals change. Step up authentication is applied when risk increases, and weak factors are not accepted for sensitive resources.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.