Federation
Trusting another organization's identity provider so its users can authenticate with their home identity while being authorized locally as a guest.
Federation moves the authentication door to the partner organization, but it doesn’t move the responsibility — the receiving organization still owns what a federated guest is authorized to do inside its own systems, and still has to remove that access when the relationship ends.