UPDATE ......From Tuesday 8 April 2025 we have changed the way that Single Sign-on works on this wiki. Please see here for more information:
Update
...
In some of the use-cases the IdP acts as a broker collecting attributes from different sources, whereas in some other scenarios the SP contact the IdP and the trusted AA to collect the attributes.
ACTION: Roland to create a small group to prepare a paper detailing the use-cases and the implications on the trust model.