entitlements-api
Manages scope and role entitlements for API consumers and users. Entitlements define what a client (API consumer subscription) or identity (user from identities-service) is authorised to access, anchored to an organisational context (application, version, functional area, group, team). This service is the authorization mapping layer — it does not own identity or client data. Identities come from identities-service (golden source), clients come from clients-service (subscription consumers). Entitlements-service maps them onto scopes and roles via delegates. Delegation model: an EntitlementDelegate links an Entitlement + Client + optional Identity, with an optional approval workflow (DelegateApproval).