Redacted provider account evidence, distinct from connector identity.
@type t() :: %ASM.RuntimeAuth.ProviderAccountIdentity{ evidence: map(), identity_status: atom(), provider: atom(), redacted?: boolean(), ref: String.t() }