A set of rules, part of an access control policy, by which credentials are matched against claims of identity.