The domain space Single Authentication Realm is a system of LDAP Groups managed by a central authority.
Basically, I will trust you on a device if Apple and Google do to a first level, to establish a putative actually known person.
The AKPERSON variant on the inet org entity is definitionally that the person has been authenticated in a transaction in the last 90 days, so that must have happened for at least a token amount, possibly charged back minus any tx fees.
Additionally, DCP will attempt to maintain the veracity of the identification of accounts with natural individuals.