Cap
nsdef:capcap — a capability a role is OFFERED: cap:<name>@<fingerprint8> names one, the fingerprint being the running seed's content_fingerprint (the P3 identity rule). Membership of set:cap:offered:<society>:<role> is what a role MAY be granted; the grant check decides what it IS granted (offered ≠ granted, B5 §A7).