OptionalidentityThe caller's principal id in the guarded resource's own namespace
(what that lake's identity() returns), resolved as identity() in
the predicate. Advisory — the engine takes the caller's word for who
is acting; only the lake's own token identity is authenticated.
Inputs to predicate evaluation: the delta-mode natives
before()/after(), themutation, theguard, andidentity().beforeis null on create,afternull on delete.