Looking at the security domain subsystem I see that that the
authorization flag field has an allowed list of:
"allowed" => [
However, the default model (what you get with a fresh new AS7 install)
has the flag value in lowercase:
"flag" => "required",
Suggestion from Brian: allow the input to be lenient, but require that the output of the model information always matches the 'allowed' range.