the enrollment family
the profile
Optionalentry: any
optional { kind, id }: an application's own list,
where it has one, is asked instead of the realm's
Optionaloptions: any
structural: true asks only whether it is an issued
profile at all, not whether it is allowed
ok and the profile, or a refusal
Checks that a profile exists, is not refused, and is allowed for a family in this realm.