“[@mention:449693036337664795] I'm afraid I missed you point on 2.1.3 : "the Circle retains the right [...] to define [...] Policies that further grant or constrain the Role’s authority within the Domain" => my understanding is that I can have a role with a domain, and a policy at the circle level which constrains the role authority over that domain. So I imagine a domain "Room xxx" on a role and a policy at the circle level allowing use of this room outside "DRP events" would do. What do you think ?“

My interpretation is that you can delegate a domain and have a policy saying that other roles can impact that domain within certain conditions (2.1.3) but it would be weird to give the property to someone and then allow others to have impact on it...