Stable actor identifier from the host authentication system.
OptionalkindAbsent means 'human', so an existing host keeps its exact behavior.
Role used by the middleware's exact allowlist. Meaningful only for the
'human' kind; for automated kinds the role allowlist is not consulted at
all and hosts should project the least-privileged label. See
authorizeActor.
Authenticated identity evaluated by RBAC and attached to audit events.