Annex E: Role-Obligation Matrix

Cross-reference between roles and requirements.

Req ID

Description

Ctrl

Dept

WAL

VER

RP

IPE

GOV

HCP

DG

DPO

AG

LAG

BOR-01

Identity is innate and inalienable

EXPT

X

                   

BOR-02

Right to management and control

EXPT

X

X

                 

BOR-03

Right to physical identity

ADMN

X

       

X

         

BOR-04

Right to not be compelled to use digital

ADMN

X

       

X

         

BOR-05

Right to endorsement on uniform standard

EXPT

X

     

X

           

BOR-06

Right to legislatively established stand

ADMN

X

                   

BOR-07

Right to transparency

EXPT

X

                   

BOR-08

Right to choose disclosed attributes

AUTO

X

X

X

               

BOR-09

Right to service regardless of format

ADMN

     

X

 

X

X

       

BOR-10

Right to freedom from surveillance

AUTO

X

X

                 

BOR-11

Right to not surrender device

AUTO

   

X

X

 

X

         
                           

PRG-01

SEDI issuance compliance

EXPT

X

                   

PRG-02

Publish technical standards

EXPT

X

                   

PRG-03

Data governance standards

EXPT

X

                   

PRG-04

45-day public comment period

ADMN

X

                   

PRG-05

Response to public comments

ADMN

X

                   

PRG-06

Fee structure publication

ADMN

X

                   

PRG-07

Annual program reporting

ADMN

X

                   

PRG-08

Program manager qualifications

ADMN

X

                   

PRG-09

Interagency coordination

ADMN

X

                   

PRG-10

Use case development

ADMN

X

                   

PRG-11

Coordination standards and guidance

ADMN

X

                   
                           

SDI-01

Compromise detection

AUTO

X

 

X

               

SDI-02

Recovery mechanisms

EXPT

X

                   

SDI-03

Cross-context correlation protections

AUTO

X

X

                 

SDI-04

Authenticity and integrity

AUTO

X

 

X

               

SDI-05

Interoperability

EXPT

X

                   

SDI-06

Online and offline presentation

AUTO

X

X

X

               

SDI-07

Selective disclosure

AUTO

X

X

                 

SDI-08

Age verification without disclosure

AUTO

X

X

                 

SDI-09

Wallet choice

AUTO

X

X

                 

SDI-10

Usability

EXPT

X

X

                 

SDI-11

Identity proofing validation

EXPT

X

     

X

           

SDI-12

Technological compliance mandate

EXPT

X

                   

SDI-13

State data center requirement

EXPT

X

                   

SDI-14

Data center best practices

EXPT

X

                   

SDI-15

Open standards mandate

AUTO

X

                   

SDI-16

Endorsed attribute set

AUTO

X

                   

SDI-17

Anti-surveillance

AUTO

X

                   

SDI-18

Purpose limitation

AUTO

X

                   

SDI-19

Individual authorization

AUTO

X

                   

SDI-20

Retention limitation

AUTO

X

                   

SDI-21

In-state data storage

EXPT

X

                   

SDI-22

Disclosure restrictions

AUTO

X

                   

SDI-23

Revocation constraints

AUTO

X

                   

SDI-24

Breach reporting

EXPT

X

                   
                           

APP-01

Age and emancipation eligibility

AUTO

X

                   

APP-02

Guardian consent for minors

AUTO

X

                   

APP-03

Guardian-initiated applications

AUTO

X

                   

APP-04

No mandatory enrollment

ADMN

X

       

X

         

APP-05

Three eligibility criteria

AUTO

X

     

X

           

APP-06

Data minimization in application

EXPT

X

                   

APP-07

Enumerated data collection fields

EXPT

X

                   
                           

IDP-01

Follow accepted proofing standard

EXPT

X

     

X

           

IDP-02

Risk-commensurate proofing

EXPT

X

                   

IDP-03

Privacy-consistent proofing

EXPT

X

     

X

           

IDP-04

Four verified assertions

AUTO

X

     

X

           

IDP-05

Sufficient for age assurance reliance

EXPT

X

                   

IDP-06

Online and offline suitability

EXPT

X

                   

IDP-07

Point-in-time endorsement

AUTO

X

                   
                           

APP-08

Fraud prohibition

ADMN

X

                   
                           

IDP-08

Independence from physical ID system

AUTO

X

                   

IDP-09

No physical document surrender

ADMN

X

                   

IDP-10

Multiple proofing methods

EXPT

X

                   

IDP-11

Proofing entity authorization

ADMN

X

                   
                           

GOV-01

No material benefit for SEDI use

ADMN

         

X

         

GOV-02

No service withholding for physical ID

ADMN

         

X

         

GOV-03

No device surrender

AUTO

         

X

         

GOV-04

New systems must accept SEDI

EXPT          

X

         

GOV-05

Technical infeasibility exemption

ADMN

         

X

         

GOV-06

Health care provider SEDI acceptance

EXPT            

X

       

GOV-07

Health care infeasibility exemption

ADMN

           

X

       
                           

WAL-01

Identity protection safeguards

AUTO

 

X

                 

WAL-02

Secure attribute processing

AUTO

 

X

                 

WAL-03

Technological compliance

EXPT  

X

                 

WAL-04

Tamper resistance

AUTO

 

X

                 

WAL-05

Online and offline presentation

AUTO

 

X

                 

WAL-06

Secure presentation log

AUTO

 

X

                 

WAL-07

Selective disclosure

AUTO

 

X

                 

WAL-08

Age predicate proof

AUTO

 

X

                 

WAL-09

Guardian presentation

AUTO

 

X

                 

WAL-10

Attribute processing limitation

AUTO

 

X

                 

WAL-11

Conspicuous notice

EXPT  

X

                 

WAL-12

Per-transaction consent

AUTO

 

X

                 

WAL-13

Primary purpose limitation

EXPT  

X

                 

WAL-14

No unauthorized retention or sharing

EXPT  

X

                 

WAL-15

Utah data protection law compliance

ADMN

 

X

                 
                           

VER-01

Identity protection safeguards

AUTO

   

X

               

VER-02

Technological compliance

EXPT    

X

               

VER-03

Secure attribute processing

AUTO

   

X

               

VER-04

Minimum attribute processing

AUTO

   

X

X

             

VER-05

Accept guardian presentations

AUTO

   

X

               

VER-06

Four-condition processing gate

AUTO

   

X

               

VER-07

No device surrender

AUTO

   

X

               

VER-08

Utah data protection law compliance

ADMN

   

X

               
                           

RPY-01

Identity protection safeguards

AUTO

     

X

             

RPY-02

Technological compliance

EXPT      

X

             

RPY-03

Secure attribute processing

AUTO

     

X

             

RPY-04

Minimum attribute processing

EXPT      

X

             

RPY-05

Accept guardian presentations

AUTO

     

X

             

RPY-06

Four-condition processing gate

AUTO

     

X

             

RPY-07

No device surrender

AUTO

     

X

             

RPY-08

Permissive SEDI acceptance

ADMN

     

X

             

RPY-09

Utah data protection law compliance

ADMN

     

X

             
                           

LOY-01

No conflicting practices

EXPT

X

X

X

X

     

X

     

LOY-02

No exploitation of individuals

ADMN

X

X

X

X

     

X

     

LOY-03

No disproportionate risk

EXPT

X

X

X

X

X

X

X

X

X

X

X

LOY-04

No detriment

ADMN

X

X

X

X

X

X

X

X

X

X

X

LOY-05

No harm

ADMN

X

X

X

X

X

X

X

X

X

X

X

                           

PRC-01

Purpose-limited record processing

AUTO

 

X

X

X

             

PRC-02

Primary purpose limitation

AUTO

   

X

X

             

PRC-03

Notice and consent for secondary use

AUTO

   

X

X

             
                           

ENF-01

Complaint submission mechanism

EXPT

X

             

X

   

ENF-02

Attorney general enforcement support

ADMN

X

X

X

X

X

X

X

X

X

X

X

ENF-03

Legislative audit

EXPT

X

                   

ENF-04

Anti-surveillance architectural proof

EXPT

X

                   

ENF-05

Audit report deadline

ADMN

                   

X

                           

CRY-01

Non-callback signature verification

AUTO

X

 

X

               

CRY-02

Holder-controlled key binding

AUTO

X

X

                 

CRY-03

Selective disclosure and predicate proof

AUTO

X

X

                 

CRY-04

Open, royalty-free algorithms

AUTO

X

                   

CRY-05

Cryptographic agility

EXPT

X

                   
                           

PRV-01

Protocol-level unlinkability

AUTO

X

X

                 

PRV-02

Leak-resistant predicate evaluation

AUTO

X

X

                 

PRV-03

Architectural anti-surveillance

EXPT

X

                   

PRV-04

Lifecycle data minimization

EXPT

X

X

X

X

X

           
                           

INT-01

Open standards for protocols and APIs

AUTO

X

                   

INT-02

Common format across presentation modes

AUTO

X

X

X

               

INT-03

Wallet portability

AUTO

X

X

                 

INT-04

No privacy-degrading fallback

EXPT

X

X

X

               
                           

KMS-01

Key lifecycle policy

ADMN

X

                   

KMS-02

Key generation ceremonies

ADMN

X

                   

KMS-03

Hardware security modules

EXPT

X

                   

KMS-04

Key rotation

AUTO

X

                   

KMS-05

Key compromise response

ADMN

X

                   
                           

ORG-01

Access management

EXPT

X

                   

ORG-02

Personnel security

ADMN

X

                   

ORG-03

Vulnerability management

EXPT

X

                   

ORG-04

Logging and monitoring

AUTO

X

                   

ORG-05

Incident response

ADMN

X

                   

ORG-06

Third-party compliance

EXPT

X

                   

ORG-07

Change management

ADMN

X

                   

 

Obligation Counts

Role

Count

Department

97

Wallet Providers

39

Verifiers

26

Relying Parties

22

Identity Proofing Entities

11

Governmental Entities

14

Health Care Providers

7

Digital Guardians

6

Data Privacy Ombudsperson

5

Attorney General

4

Legislative Auditor General

5

Total: 142 requirements