act property
Replacement act scope, in the same explicit form as the entry's (all, none, or
a non-empty context list). A replacement that WIDENS or equals the stored scope is
accepted, subject to the granter bound. NARROWING THE ACT SCOPE IS A REVOCATION and
a consumer MUST refuse it here with narrowingNotPermitted, directing the caller
to acl/revoke, so that every removal of where a subject may act passes through the
task that is audited and reasoned as a revocation.
Implementation
final AuthorityScope? act;