Implement IAL1 self-asserted identity proofing per NIST SP 800-63A Section 4.2. At IAL1 attributes are self-asserted by the applicant + no validation or verification of those attributes is required + identifier may be pseudonymous + attributes may be collected only with applicant consent. IAL1 requires (a) clear notice to applicants per Section 5.5 of what attributes are collected and how they will be used, (b) consent mechanism per Section 5.5, (c) basic fraud mitigation appropriate to risk per Section 5.4 (rate limiting + anomaly detection + abuse reporting channels), (d) record retention per agency policy and legal requirements per Section 5.3, (e) accessibility considerations per Section 9. IAL1 is appropriate for low-risk transactions where impersonation harm is minimal and no need for binding identity to a real-world person.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.