420 Identity permissions¶
Profile updates and controller transfers require the authorized profile controller. Credential issuance requires the active issuer controller. Revocation may be available to issuer control/governance according to protocol rules; subject rejection belongs to the subject profile controller.
Possessing an Identity profile or credential does not grant Smart Account capabilities or arbitrary dApp permissions.