Use when doing sec authz work for permission, privacy, boundary, dependency, and threat-model work and you need asset, actor, boundary, failure path, mitigation, and verification evidence before claiming progress.