A normalised access-control entry tied to a piece of content, translated from whatever native scheme (ACL, RBAC scope, sensitivity label) the source system used.
One or more per Source Document or Knowledge Item
Superseded on each resync; historical grants not retained by default
Only the control-bearing entities were modelled for lifecycle. Defensible as a starting point, but it does leave the entity model uneven, and this is incompleteness rather than a finding.