A.2.8.PER:4.2 - Use the closed beneficiary reference family
PermissionBeneficiaryRef ::=
exactly one branch is present:
beneficiarySystemRoleKindRef?: U.KindRef resolving to one exact local system-role kind
beneficiarySystemRoleAssignmentRef?: U.RelationRef constrained to U.SystemRoleAssignment
beneficiaryPartyRef?: PartyRef
The entity designated by the grant is its beneficiary. Apply the exercise-eligibility test for its reference branch:
beneficiarySystemRoleAssignmentRefnames one assignment occurrence and its declared species and applies only to that occurrence.beneficiarySystemRoleKindRefnames one exact local system-role kind; the policy states which current assignments to that kind make an actual performer eligible.PartyRefcovers work only when its exact performer or on-behalf-of relation satisfies the policy. Shared naming or organizational membership is insufficient.
This is a closed ref union over admitted U.Entity values, not U.PermissionBeneficiary, U.Authorization, or another new U-kind. A materially different beneficiary meaning requires a separate decision under the applicable subject pattern.