A mechanism that is used by a server to determine whether to trust a user identity during identity assertion.