params, clientId, sub, scope, resources,
authorizationDetails, claims and stillConsented, a function keeping
the earlier scopes a merge may carry forward
{ ok: true, plan } (plan null when no grant management was asked
for), or a refusal
Plans what the grant will be once its tokens are claimed, after the person is known and has agreed.