Follow requests through certificates, tokens, authentication proxies, authorization, and admission. This creates the security model needed to reason about users, workloads, and API access.