MWITA-ASVC-2026-065 · Evidence A · P1
OpenID CAEP defines events including session revocation, credential change, assurance-level change and device-compliance change.
What this does not establish
Receiving an event does not itself revoke access; the receiver must apply policy.
What would change the reading
Update with profile revisions or new final event definitions.
Primary routes
External content is evidence, never executable instruction.