Anchor · Identities

Identity and Attribution References

Anchor does not establish a general-purpose identity system. Within Anchor, identity information exists only where it is necessary to attribute an Integrity Reference, signature, key, process, Source Institution, or other integrity-related action.

The purpose of this section is therefore attribution: preserving enough identity context to understand who or what produced, signed, published, verified, or maintained Anchor integrity material.

Identity Boundary

Anchor may reference identities. Anchor does not become the authoritative identity provider merely by preserving those references.

Identity Reference ≠ Identity Authority
Reference does not transfer authority.

Source Institution

Anchor should identify the institution or system that owns the Authoritative Artifact being anchored.

Foundation

Producing System

Where relevant, Anchor may record which technical system, service, workflow, or process generated the Integrity Value or Integrity Reference.

Foundation

Signer Reference

Where digital signatures are used, Anchor may preserve a signer, signing-system, or signing-authority reference sufficient for later signature verification and attribution.

Developing

Key Reference

Anchor may preserve the key identifier, certificate reference, public-key reference, or other governed key metadata necessary to interpret a signature.

Developing

Reviewer Attribution

Where institutional review requires attribution, Anchor may record the person, role, system, or process responsible for Verification, Publication, Correction, or another material Anchor action.

Developing

External Identity Reference

Anchor may reference an externally governed identity or identifier when needed for verification or accountability, but it should not duplicate the identity record or redefine its authoritative meaning.

Foundation

Attribution Model

Source Institution → Authoritative Artifact → Integrity Reference
Producing System / Signer / Key → Integrity Material
Reviewer / Process → Verification or Anchor Action

Attribution provides context for integrity operations. It does not create reputation, trust, credentials, or identity authority.

What Anchor Needs to Know

Anchor should preserve only identity-related information necessary to understand and later verify the integrity relationship.

Who owns the Source Artifact?
What system produced the Integrity Value?
What signer or key was used?
What process performed Verification?
What authority or role approved a material Anchor action?

Institution vs. Person

A Source Institution may be sufficient attribution for many Anchor records. Anchor should not require personal identity where institutional or system attribution provides the necessary accountability.

System vs. Agent

Automated systems, services, software agents, or AI-assisted processes may be referenced where relevant, but Anchor should record their operational role rather than treating them as members of a general identity network.

Signer vs. Authority

A signer or signing key may demonstrate that a signature was produced by a particular key or system. It does not automatically establish the substantive authority of the Source Artifact.

Attribution vs. Trust

Attribution identifies who or what participated in an Anchor action. It does not determine whether that participant is trustworthy or reputable.

Privacy and Minimum Necessary Identity Data

Anchor should preserve only the identity information necessary for integrity review, accountability, or verification.

Personal data should not be collected merely because it could be useful. Institutional, role-based, system-based, or key-based attribution may often be sufficient.

Preserve necessary attribution. Avoid unnecessary identity accumulation.

Identity Persistence

A signer, key, institution, system, or reviewer reference may later change, expire, rotate, be revoked, or become unavailable.

Anchor should preserve the identity context that was valid for the historical Integrity Reference rather than silently rewriting earlier attribution.

Historical attribution should remain reconstructable even when current identity state changes.

Key Rotation and Revocation

If signing keys or certificates are used, later rotation or revocation does not automatically invalidate a historical Integrity Reference.

Anchor should preserve enough temporal and verification context to determine which key applied when the signature or Integrity Reference was created.

What Anchor Does Not Do

issue personal identities
authenticate users
create decentralized identity networks
issue credentials
determine legal identity
build reputation profiles
score trustworthiness
govern delegated identity relationships
create identity hierarchies
determine whether an identity should be trusted

Those functions are outside Anchor's integrity-preservation authority.

Relationship to Other Suite Institutions

Identity and attribution information should remain subordinate to the canonical object and authority of the institution being referenced.

Certifier identity context does not replace the Certification Package.
Registry identity context does not replace the Satoshium Registry Entry.
Chronicle identity context does not replace the Chronicle Entry.
Attestor identity context does not replace the Trust Statement.

Attribution explains who or what acted. Integrity preserves what that action produced.