Files
ohm-content/rfcs/identity.md
T
ben.stull 70c79c6768
regenerate-readme-index / noop (push) Has been cancelled
Add Identity and Relationality RFC super-drafts
Expand RFC-0001 §Identity and §Relationality into proposed super-drafts. Identity: persona, linkability/selective disclosure, plural-presentation but singular-standing. Relationality: the flow, contextual integrity, per-edge asymmetric consent. Both depend on Informed Consent; neither graduated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 08:56:49 -07:00

6.9 KiB

slug, title, state, id, repo, proposed_by, proposed_at, graduated_at, graduated_by, owners, arbiters, tags
slug title state id repo proposed_by proposed_at graduated_at graduated_by owners arbiters tags
identity Identity super-draft null null ben.stull@wiggleverse.org 2026-06-12 null null
ben.stull@wiggleverse.org

RFC-0001 (Human) establishes Identity as one of the five foundational properties of a Human and names it among the words still to be defined. It also leaves three of its hardest questions open: how to represent the same Human across different contexts without flattening them into a single canonical profile, what the relationship is between a Human and their digital representations or proxies, and how self-claimed identity is weighted against the identity the world ascribes. This RFC takes up Identity as that specification. It does not reopen what RFC-0001 already settled — that a Human carries a persistent sense of self that is internal and external, plural, claimed-and-ascribed, and continuous through change — it specifies how a system may represent and reference that self without betraying it. Where the sibling RFC, Relationality, governs what may be shared between Humans, Identity governs what may be recorded about one.

The central move is to separate three things that systems routinely conflate: the Human's identity, the identifiers that reference it, and the personas through which it is presented. RFC-0001 already holds that a legal name, a username, or a government ID is attached to identity but is not identity — these are how particular systems point at a Human. This RFC adds the layer between identifier and identity: the persona, a curated, partial, context-and-audience-specific presentation of the one identity. A single Human has a single identity and may wear many personas — the maker and the buyer, the public voice and the private correspondent, the professional and the kin — without thereby being many Humans and without holding many identities. RFC-0001's commitment that "the model must not collapse this plurality into a single canonical profile, nor treat contextual variation as inconsistency" is the floor; the persona is the construct that honors it. A persona is a presentation of the one plural identity, not a fragment that competes with it.

If identity is plural and presented through many personas, the question that decides whether the model protects a Human or exposes them is linkability: whether two personas can be recognized as belonging to the same Human. This RFC takes the position that linkability is not a system default but a disclosure the Human holds authority over — Epistemic Authority and Informed Consent applied to identity itself. The default, inherited from Privacy & Data Minimization, runs toward unlinkability: a system should not silently correlate a Human's personas, and should record only the identifiers an interaction genuinely requires. Linking two personas — letting an audience that knows a Human in one context recognize them in another — is a specific, purpose-bound, revocable act of consent, never a convenience the platform may assume. This is what lets a single Human be private in one relationship and recognized in another without contradiction, and it is the property on which every downstream claim of cross-context privacy or sovereignty ultimately rests.

The plurality of personas must not, however, become a route to multiplying a Human's standing. A persona is a face, not a separate source of authority. A Human cannot use plural presentation to fabricate independent endorsement of themselves, to escape under a second persona the accountability earned under a first, or to count once-per-Human trust more than once. This RFC therefore distinguishes what attaches to a persona — presentation, context-specific reputation, audience-specific visibility — from what attaches to the Human beneath it: singular standing, accountability across personas, and the limit that trust extended to "a Human" cannot be inflated by spawning more personas. How that limit is enforced in a given deployment — verification, staking, Sybil-resistance — is downstream (Reputation, Trust & Safety). What this RFC fixes is that the limit exists and where it binds: presentation is plural; standing is singular.

Identity is both self-claimed and world-ascribed, and the two do not carry equal weight. Where a Human asserts who they are — their name, their pronouns, which personas are theirs, how they wish to be addressed — that self-claim carries the distinctive epistemic weight RFC-0001 assigns to self-knowledge, and the model treats it as primary. Identity the world ascribes — categories assigned by institutions, inferences drawn by systems, the recognition or misrecognition of others — is secondary, must be marked as such, and must be contestable: a Human needs a path to challenge an ascription a system has attached to them. This is the internal and external face of RFC-0001's Identity, given a rule of precedence: the internal face leads, and the model owes visibility and recourse wherever an external ascription overrides it.

This RFC builds directly on RFC-0001 (Human) and is the sibling of Relationality. It depends on Informed Consent (the permission account for what is recorded and for any linkage across personas), Privacy & Data Minimization (the default toward minimal identifiers and unlinkability), and Epistemic Authority (the primacy of self-claim). It conditions Participants (a role — Customer, Merchant, Operator — is one kind of context a persona is worn in), Reputation (which attaches per-persona but can never exceed the Human beneath it), Durable Addressability (the stable path a persona is reached at, preserved across change), and Exit & Portability (a Human's standing to take their identity and personas with them when they leave). It does not settle the identity of non-human entities, which their own RFC addresses, though it must eventually say how a Human's proxies and agents present on the Human's behalf.

Identity, in OHM, is therefore not the set of identifiers a system holds, not an account, not a single canonical profile, and not a license to treat a Human's several personas as several Humans. Open questions this RFC will have to resolve as it graduates: how much linkage across personas is the Human's to control versus legitimately ascribed by others (a creditor, a court, or a safety system may have standing to link where the Human would not consent); how per-persona reputation composes when personas are later, consensually, linked; how a persona is handled after the Human's death, or when a proxy presents for a Human who cannot consent for themselves (conditioned by RFC-0001's Personhood position); how identifiers may rotate while preserving continuity of identity (in concert with Durable Addressability); and what the minimum viable identity is for a given interaction, degrading gracefully when less is known — RFC-0001's open question, inherited here and made sharper by the persona.