A draft start for discussion kick-start purposes only

Types of signed metadata aggregates:

  1. MDA (metadata aggregates)
    1. Export
      1. international interfed export
      2. private (aka local) : Where the IdPs and SPs in this MDA are all registered/owned by the parent Org
      3. private (aka custom): Where the MDA contains a custom set of IdPs and SPs, a subset of InCommon MD plus any private IdPs/SPs not in the InCommon public MDA
    2. Import
      1. Importing an international set of IdPs or SPs
      2. Importing a set from a single Org
  2. Per Entity MD: That is, InCommon signs a metadata blob containing one SP or IdP entityDescriptor

Here's another way to look at it

Types of signed metadata aggregates: