Identity Boundary
Anchor may reference identities. Anchor does not become the authoritative identity provider merely by preserving those references.
Anchor does not establish a general-purpose identity system. Within Anchor, identity information exists only where it is necessary to attribute an Integrity Reference, signature, key, process, Source Institution, or other integrity-related action.
The purpose of this section is therefore attribution: preserving enough identity context to understand who or what produced, signed, published, verified, or maintained Anchor integrity material.
Anchor may reference identities. Anchor does not become the authoritative identity provider merely by preserving those references.
Anchor should identify the institution or system that owns the Authoritative Artifact being anchored.
FoundationWhere relevant, Anchor may record which technical system, service, workflow, or process generated the Integrity Value or Integrity Reference.
FoundationWhere digital signatures are used, Anchor may preserve a signer, signing-system, or signing-authority reference sufficient for later signature verification and attribution.
DevelopingAnchor may preserve the key identifier, certificate reference, public-key reference, or other governed key metadata necessary to interpret a signature.
DevelopingWhere institutional review requires attribution, Anchor may record the person, role, system, or process responsible for Verification, Publication, Correction, or another material Anchor action.
DevelopingAnchor may reference an externally governed identity or identifier when needed for verification or accountability, but it should not duplicate the identity record or redefine its authoritative meaning.
FoundationAttribution provides context for integrity operations. It does not create reputation, trust, credentials, or identity authority.
Anchor should preserve only identity-related information necessary to understand and later verify the integrity relationship.
A Source Institution may be sufficient attribution for many Anchor records. Anchor should not require personal identity where institutional or system attribution provides the necessary accountability.
Automated systems, services, software agents, or AI-assisted processes may be referenced where relevant, but Anchor should record their operational role rather than treating them as members of a general identity network.
A signer or signing key may demonstrate that a signature was produced by a particular key or system. It does not automatically establish the substantive authority of the Source Artifact.
Attribution identifies who or what participated in an Anchor action. It does not determine whether that participant is trustworthy or reputable.
Anchor should preserve only the identity information necessary for integrity review, accountability, or verification.
Personal data should not be collected merely because it could be useful. Institutional, role-based, system-based, or key-based attribution may often be sufficient.
A signer, key, institution, system, or reviewer reference may later change, expire, rotate, be revoked, or become unavailable.
Anchor should preserve the identity context that was valid for the historical Integrity Reference rather than silently rewriting earlier attribution.
If signing keys or certificates are used, later rotation or revocation does not automatically invalidate a historical Integrity Reference.
Anchor should preserve enough temporal and verification context to determine which key applied when the signature or Integrity Reference was created.
Those functions are outside Anchor's integrity-preservation authority.
Identity and attribution information should remain subordinate to the canonical object and authority of the institution being referenced.
Anchor should preserve enough identity context to make integrity actions attributable and reviewable without becoming a general identity institution.