The risk that attackers obtain valid credentials (for example via phishing or social engineering) or that insiders abuse legitimate access.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.