Tech4Humanity AtlasGround ZeroCurrent ThemesFuture ResearchGalleryLive Q&ASearch

Consent, Identity & Human Agency / Digital Identity

SUB-T04-003 · Story

Identity Portability

I could prove that I had built bridges. I could not make the new system believe me. My qualifications were valid, my employment history was documented and my referees were reachable. None of it moved cleanly across borders, platforms or institutions. That human situation is the reason this subtopic exists. The problem is not simply that current systems are imperfect. Identity Portability is often implemented through complex interfaces, weak evidence, implied authority or broad permissions that do not reliably reflect the person’s intention, capacity or continuing consent. The research asks: How can identity portability be designed and governed so that identity, consent and authority remain accurate, understandable, revocable, contestable and aligned with the person’s actual intentions? Its working hypothesis is deliberately narrower than the story around it: A purpose-limited, evidence-backed and revocable approach to identity portability, with explicit authority boundaries and human-readable controls, will improve user agency, reduce misuse and increase decision legitimacy compared with opaque, bundled or non-revocable approaches. This distinction matters. The scenario explains why the question deserves attention; it does not pretend that the answer has already been proven. The proposed work combines policy and standards analysis; consent-flow mapping; identity and access-control testing; user research; threat modelling; adversarial simulation; usability and comprehension testing; audit-log analysis; rights-impact assessment; methods adapted specifically to identity portability The evidence is expected to include measures such as comprehension testing; task completion; false acceptance and rejection; scope violations; revocation latency; appeal outcomes; subgroup disparity; user-reported agency; privacy impact Rather than rewarding a system for one attractive short-term result, the design examines performance alongside burden, agency, equity, safety, recovery and what happens when assistance is removed or conditions change. For the people involved, the practical change would be felt before it became an abstract score. A child might retain more choice. A professional might regain enough uninterrupted attention to exercise judgement. A family might spend less time proving the same facts to disconnected services. An institution might recognise uncertainty before it hardens into harm. There are still important unknowns: Effect size; legal variation; cross-border recognition; proofing quality; accessibility; cultural expectations; adversarial adaptation; optimal assurance level; institutional adoption cost. These are not footnotes to be hidden. They define the work that still has to be done and the boundary between an evidence-informed possibility and a validated conclusion. What could become distinctive is a human-agency assurance protocol for identity portability linking identity, authority, purpose, consent, execution, evidence, revocation and recovery. Failures in identity portability can expose people to identity fraud, unauthorised decisions, coerced data use, loss of access, unfair exclusion, surveillance and diminished human agency. Portable identity is not one universal profile. It is the ability to carry trustworthy claims without surrendering control of the whole person.

To carry the scenario into an executable research setting, the team in United Kingdom would next translate the question into a pre-registered comparison. They would vary assurance level; disclosure quality; consent granularity; authority scope; revocation design; human review; auditability; data minimisation; implementation context and observe comprehension; accuracy; authority fidelity; misuse rate; user control; revocation success; appeal success; trust; privacy impact, while recording digital literacy; disability; language; urgency; power imbalance; age; service dependency; legal context; prior trust; document availability. This is a proposed study path, not a report of completed results. It preserves the original story's purpose while making the evidentiary boundary explicit.

Aroha, acting as the clinical researcher at a regional health service, would also require a handback test: participants must be able to question the assistance, pause it, recover from an error and complete a later task without it. That requirement turns identity Portability from an attractive feature into a falsifiable human-capability claim. A supported hypothesis could inform products and services in health and care; an unsupported hypothesis would prevent premature scale and redirect future research.

Reflection

What did we learn?: The scenario shows why identity Portability must be evaluated as a human-capability claim, not inferred from activity or short-term output. It also shows why assistance, burden, agency, subgroup effects, handback and recovery belong in the same evaluation.

Why does this matter?: Failures in identity portability can expose people to identity fraud, unauthorised decisions, coerced data use, loss of access, unfair exclusion, surveillance and diminished human agency.

What research does this connect to?: This subtopic sits within Digital Identity and draws on privacy law, identity management, human rights, cybersecurity, access control, administrative law, human–computer interaction and AI governance. Existing implementations often separate technical access from lawful authority. Related subtopics: Identity Proofing; Identity Resolution; Pseudonymous Identity.

What should happen next?: Complete authoritative legal, standards and literature scan for Identity Portability; appoint owner; map the authority and consent flow; define test scenarios and measures; convene affected-user and expert review; draft rights, ethics and study protocol.

Research connection

Hypothesis: A purpose-limited, evidence-backed and revocable approach to identity portability, with explicit authority boundaries and human-readable controls, will improve user agency, reduce misuse and increase decision legitimacy compared with opaque, bundled or non-revocable approaches.

Scientific uncertainty: Effect size; legal variation; cross-border recognition; proofing quality; accessibility; cultural expectations; adversarial adaptation; optimal assurance level; institutional adoption cost.

Variables: Independent variables: assurance level; disclosure quality; consent granularity; authority scope; revocation design; human review; auditability; data minimisation; implementation context. Outcomes: comprehension; accuracy; authority fidelity; misuse rate; user control; revocation success; appeal success; trust; privacy impact. Confounders: digital literacy; disability; language; urgency; power imbalance; age; service dependency; legal context; prior trust; document availability.

Research methods: Policy and standards analysis; consent-flow mapping; identity and access-control testing; user research; threat modelling; adversarial simulation; usability and comprehension testing; audit-log analysis; rights-impact assessment; methods adapted specifically to Identity Portability.

Evidence: Authoritative legal and standards sources; validated measures for comprehension testing; task completion; false acceptance and rejection; scope violations; revocation latency; appeal outcomes; subgroup disparity; user-reported agency; privacy impact; representative user testing; documented authority chains; pre-registered protocol; adverse-event scenarios; accessibility and subgroup analysis; audit logs; appeal and recovery records.

Frameworks: Authority–Purpose–Consent–Execution–Evidence–Revocation model applied to Identity Portability: identify who acts, for what purpose, under which authority, against what constraints, with what evidence and how authority can be revoked.

Links: NIST Digital Identity Guidelines — https://pages.nist.gov/800-63-3/; W3C Verifiable Credentials — https://www.w3.org/TR/vc-data-model/; ISO/IEC 24760 identity management; Australian Digital ID Act 2024 — https://www.legislation.gov.au/.

Commercialisation and public value

Products: Consent ledger; identity wallet; delegation registry; authority verifier; revocation engine; agency dashboard; rights and appeals workflow; dedicated identity portability benchmark.

Services: Enterprise and public-sector subscriptions; consent and identity APIs; assurance and audit services; wallet and delegation modules; implementation support; regulated-sector evidence packs; training and certification.

Industries: Government services; health; finance; education; employment; legal services; online platforms; AI agents; data sharing; identity verification; delegated decision-making.

Government: Individuals; families; workers; consumers; platforms; governments; identity providers; regulators; legal practitioners; financial institutions; health and social services.

Policy: Privacy; informed consent; digital identity; automated decision-making; delegation; data portability; revocation; procedural fairness; human rights; identity fraud.

Future research: Complete authoritative legal, standards and literature scan for Identity Portability; appoint owner; map the authority and consent flow; define test scenarios and measures; convene affected-user and expert review; draft rights, ethics and study protocol.

Business opportunity: Develop a reusable identity portability framework, benchmark, evidence model and operational workflow for wallets, identity services, consent systems, AI agents, institutions and regulated services.

Scenario narrative — not an empirical finding.