Skip to content

Create a CAWG Governance Assertion to Indicate a Governing Authority's authorization over a CAWG Assertion #263

Description

@ScottSPerryCPA

In the decentralized ecosystem of CAWG assertions, the right of individuals and organizations to make specific CAWG assertions (identity, consent, metadata etc.) will be governed by many sources (and may happen multiple times within one manifest). We need the ability to denote the express directive of a governing authority for CAWG claims directly on the asset itself.

Eric Scouten and I have noodled about how this can be done and we're leaning towards creation a new unique assertion, the Governance Assertion. This assertion could include an organizational certificate (or VC) from a governing authority, a link to a trust registry of approved signers, and referenced assertions that this governance assertion pertains to.

As we look to creating a CAWG identity trust model outside of the Mozilla Trust Store, we can use this new governance assertion to link to a CAWG trust list.... It can be used for authorities that govern specific metadata to authorize the injection of the data, It can be used by authorized individuals to make consent claims on data.

Here are a few additional notes and discussion topics:

"Who authorized this? Who gives you the right to say ___?"

How could this be abused (i.e. by authoritarian governments?)

Who is given the right to make an assertion? Where is a link to the governance framework?

(Let's talk about the naming of this.)

In a sentence, what statement are we enabling? I think it's: "I am member of X, and (optional) that allows me to say Y about this asset."

We need to better understand how to prove and validate the "I am a member of X" statement. Trust registry? Credential endorsement?

What is in this assertion? An organizational cert that provides a traceable reference to a trust registry?

Maybe this becomes a governed metadata assertion? You only process the data if you understand, accept, and can validate the governance rules of that domain/organization.

Statement: "A third party is claiming that you have the right to make ___ claim."

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Fields

No fields configured for issues without a type.

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions