Seednote

Issuance authority

Who may issue, and what that does not confer

A registered issuer permitted to issue identities within a delegated namespace.

RSM ID Learning Center2 min read

An issuance authority is a registered, authenticated controller that may issue RIDs and register names within a namespace it has been delegated. Authority must be proven before issuing under a prefix, and the registry keeps every delegation, key rotation, transfer, and revocation as an auditable record. Only properly delegated issuers create authoritative identity records.

Authority is a governance relationship with a namespace, not with the things named in it. An authority may delegate issuance and space administration without transferring ownership of any resource represented in those spaces, and a conforming issuer must never claim globally authoritative issuance under an unregistered or unverified prefix.

Example

In the resolver demonstration, a fictional regional network, willowcreek, issues identities under delegated authority for its farms, mill, and watershed. The farm's name is rrn:451:willowcreek:us-ca:willowcreek:organization/willow-creek-farm, and the network's own space has the illustrative RID 451.JX39VP1PX9NAJCMQ. Issuing the farm's RID does not make the network the farm's owner.

A common misconception

“Whoever issued the identifier owns the resource.” Issuance confers no legal ownership, consent, access rights, or authority to disclose sensitive knowledge. The issuer, the legal owner, the custodian, and the community entitled to steward knowledge may all be different parties, and RSM governance represents them separately.

Authority is exercised under a prefix and recorded in the registry. The distinction from ownership has a Fieldnote of its own.

In the specification

Registry trust: Document 08 §5.4. Delegation without ownership: §4.6. Namespace authorization: §11.2. Issuer conformance: §14.2.