Limits of SEMA RBAC Conflict Resolution with Expired Credentials
Context SEMA’s role‑based access control (RBAC) assigns permissions to roles rather than individual users, aiming to enforce least‑privilege. Credentials can be flagged as expired; when used, SEMA denies access to protected resources. However, the policy language does not specify how to resolve conflicts when a user holds multiple roles that grant overlappin