AUTHENTICATION
Two protected channels
- RP-to-Trusted-SIC: mTLS + OAuth2 client credential or private-key JWT
- User approval: OIDC session + WebAuthn challenge/assertion
- Scopes: signing.request, signing.approve, signing.execute, evidence.read
- Audience, tenant, RP and purpose are mandatory authorization facts
