Background
When organisational affiliation is used for authorisation (or any similar purpose), it is necessary for a RP to know whether they can trust the attribute.
For a community proxy relaying information about the user (see AARC-G056), the affiliation may have been verified in the past by the user registering with their then home organisation, but the user has continued to log in with a linked lower assurance account.