//! Conditional-access policy evaluation and per-client claims transformation.
//!
//! Two pure, transport- and storage-free engines that back Entra-style
//! "conditional access" and "claims mapping":
//!
//! - [`access`] — evaluate a tenant's conditional-access [`Policy`](access::Policy)
//! set against one sign-in and combine into a single grant / block / step-up
//! [`Verdict`](access::Verdict).
//! - [`claims`] — apply an app registration's [`ClaimMapping`](claims::ClaimMapping)
//! list to produce the extra custom claims for its tokens.
//!
//! The caller resolves the sign-in facts (groups, IP, device posture, risk)
//! and owns all persistence; these modules only decide.
pub use ;
pub use ;