Skip to main content

Roles and Responsibilities

UbID separates responsibilities so that no single participant is assumed to own every aspect of identity. This separation is central to privacy, security, interoperability, and accountability.

Primary roles

RoleCore responsibilityMust not assume
Issuer organizationEstablishes the truth, authority, and governance of the claims it issues.That a cryptographic signature alone proves the original evidence was accurate.
Credential holderControls custody and authorizes presentation of credentials.That holder control allows institutional claims to be altered.
Wallet or vaultProvides protected custody, consent, presentation, and device continuity.That it can make the verifier's policy decision.
VerifierRequests evidence and validates provenance, integrity, status, freshness, and policy.That every valid credential is sufficient for every transaction.
Relying partyUses the verification result for a service, eligibility, or access decision.That the platform replaces the institution's legal and business responsibilities.
Custodian or recovery participantAssists continuity only under explicit authorization and policy.That recovery assistance grants unrestricted control of the holder's identity.
Platform operatorMaintains services, security controls, operational evidence, and governed availability.That operating infrastructure makes it the owner of every credential claim.

Issuer responsibility

An issuer is accountable for the claims it makes. It must define:

  • the credential purpose and intended audience;
  • the evidence required before issuance;
  • who is authorized to approve issuance;
  • how claims are corrected, renewed, suspended, or revoked;
  • the assurance and retention rules associated with the credential;
  • how signing authority and credential status are governed.

The issuer's signature proves provenance and integrity. It does not remove the need for a sound proofing and approval process.

Holder responsibility and agency

The holder controls the custody and presentation of credentials. This includes reviewing requests, authorizing disclosure, managing devices, and initiating approved recovery when necessary.

Holder agency should be meaningful. A person should be able to understand what is requested, which claims will be disclosed, and which institution will receive them. The experience should not encourage unnecessary disclosure simply because more data is available.

Verifier and relying-party responsibility

A verifier evaluates whether presented evidence satisfies a policy. A relying party uses that outcome to make a decision.

The verifier should request only the evidence needed for the declared purpose and should validate more than the signature. Depending on the use case, verification may include status, freshness, audience, issuer trust, holder relationship, and assurance level.

The relying party remains responsible for proportionality, legal basis, fairness, sector rules, and the consequences of its decision.

Wallet and platform responsibility

A wallet protects holder-controlled material and supports consent. The platform provides the services, trust contracts, cryptographic controls, interoperability, and operational evidence needed for the ecosystem to work.

Neither should silently make decisions that belong to another role. Experience channels present choices; domain services evaluate trust; relying institutions decide how to act on the result.

Recovery responsibility

Recovery must not collapse all control into one administrator. Recovery participants should release only the assistance permitted by explicit policy and authorization. The process should distinguish identity verification, authorization, preparation, release, restoration, and post-recovery rotation.

Shared accountability

Holder control does not eliminate institutional duties. Institutional authority does not justify unlimited collection. Cryptographic validity does not replace policy. UbID is designed so that each participant can perform its role while leaving evidence that can be independently reviewed.