While WS-Trust provides the primitives for playing the token issuing game, WS-Federation builds on those capabilities and enables to describe the behavior of complex scenarios. Microsoft and IBM recently published a joint whitepaper, titled Understanding WS-Federation, which gives exhaustive descriptions of the specification in action on various notable situations. Namely, the paper really goes in fine details of how WS-Federation handles sing in and resource access management in two fairly realistic scenarios, about enterprise and healtcare (I suspect Roberto is behind the latter :-)). Both the passive and active case are considered. Besides fulfilling its obvious purpose of explaining how WS-Federation work, the paper is a great way of stimulate your thinking about the nuances that emerge in canonical (yet realistic) federation scenarios.
P.S.: I SO need to find a good synonym for “scenario”.