Identity versus entity context
Officially, a KSeF certificate carries its authenticated owner's identity. It contains no KSeF permissions and is not assigned to a company context; KSeF evaluates permissions server-side for the context requested. The same certificate may therefore work across entities where its owner is authorized and fail elsewhere. Certificate-management endpoints concern the authenticated owner and expose that owner's same certificate set regardless of login context. As a recommended governance control, document credential owner separately from legal entity, workload and granted role. IAM should approve the context map, while finance confirms entity scope. Acceptance means every inventory record names one authenticated owner, every intended context has separate permission evidence, and no architecture diagram suggests that possession of the credential grants company access.