Implement and periodically review access controls including technical and physical controls to authenticate and permit access only to authorized users and limit authorized users access to customer information that they need to perform their duties.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.