Why does SL1 need to specify an access token? While they are used for userinfo calls -- it is generally a one time use. I think we need to clarify what else besides userinfo we would need.
Building on that, it would seem access tokens for other resources that may be at the identity service to be out of scope.
How an RP manages its own 1P access / refresh tokens is also important, but I think independent of session lifecycle with the exception that the RP should be able kill refresh tokens.