Annex G: Roles and Actors

4.1 Overview of the SEDI Ecosystem

The SEDI ecosystem comprises the following roles, each with distinct statutory obligations. An entity may serve multiple roles simultaneously (e.g., a governmental entity may also be a relying party).

4.2 Department / Program

Statutory authority: Utah Code §§ 63A-20-202203

The Department of Government Operations operates the SEDI program. In identity ecosystem terms, the Department is the issuer: the entity that endorses (digitally signs) the holder's identity attributes, binding them to the holder's personal digital identifier. The Department also sets standards, approves conformance profiles, and operates the issuance and revocation infrastructure.

Key constraint: The Department's role ends at issuance. The statute prohibits the Department from monitoring, surveilling, or tracking presentations (Utah Code § 63A-20-301(3)).

Obligations applicable to this role:

Req ID

Short Description

Control

Source

Bill of Rights

     

SEDI-BOR-01

Identity is innate and inalienable

AUTO

Part 1

SEDI-BOR-02

Right to management and control

AUTO

Part 1

SEDI-BOR-03

Right to physical identity

ADMN

Part 1

SEDI-BOR-04

Right to not be compelled to use digital

ADMN

Part 1

SEDI-BOR-05

Right to endorsement on uniform standards

AUTO

Part 1

SEDI-BOR-06

Right to legislatively established standards

ADMN

Part 1

SEDI-BOR-07

Right to transparency

EXPT

Part 1

SEDI-BOR-08

Right to choose disclosed attributes

AUTO

Part 1

SEDI-BOR-10

Right to freedom from surveillance

AUTO

Part 1

Program

     

SEDI-PRG-01

SEDI issuance compliance

EXPT

Part 2

SEDI-PRG-02

Publish technical standards

EXPT

Part 2

SEDI-PRG-03

Data governance standards

EXPT

Part 2

SEDI-PRG-04

45-day public comment period

ADMN

Part 2

SEDI-PRG-05

Response to public comments

ADMN

Part 2

SEDI-PRG-06

Fee structure publication

ADMN

Part 2

SEDI-PRG-07

Annual program reporting

ADMN

Part 2

SEDI-PRG-08

Program manager qualifications

ADMN

Part 2

SEDI Core

     

SEDI-SDI-01

Compromise detection

AUTO

Part 3

SEDI-SDI-02

Recovery mechanisms

EXPT

Part 3

SEDI-SDI-03

Cross-context correlation protections

AUTO

Part 3

SEDI-SDI-04

Authenticity and integrity

AUTO

Part 3

SEDI-SDI-05

Interoperability

EXPT

Part 3

SEDI-SDI-06

Online and offline presentation

AUTO

Part 3

SEDI-SDI-07

Selective disclosure

AUTO

Part 3

SEDI-SDI-08

Age verification without disclosure

AUTO

Part 3

SEDI-SDI-09

Wallet choice

AUTO

Part 3

SEDI-SDI-10

Usability

EXPT

Part 3

SEDI-SDI-11

Identity proofing validation

EXPT

Part 3

SEDI-SDI-12

Technological compliance mandate

EXPT

Part 3

SEDI-SDI-13

State data center requirement

EXPT

Part 3

SEDI-SDI-14

Data center best practices

EXPT

Part 3

SEDI-SDI-15

Open standards mandate

AUTO

Part 3

SEDI-SDI-16

Endorsed attribute set

AUTO

Part 3

SEDI-SDI-17

Anti-surveillance

AUTO

Part 3

SEDI-SDI-18

Purpose limitation

AUTO

Part 3

SEDI-SDI-20

Retention limitation

AUTO

Part 3

SEDI-SDI-21

In-state data storage

EXPT

Part 3

SEDI-SDI-22

Disclosure restrictions

AUTO

Part 3

SEDI-SDI-23

Revocation constraints

AUTO

Part 3

SEDI-SDI-24

Breach reporting

EXPT

Part 3

Application & Proofing

     

SEDI-APP-01

Age and emancipation eligibility

AUTO

Part 3

SEDI-APP-02

Guardian consent for minors

AUTO

Part 3

SEDI-APP-03

Guardian-initiated applications

AUTO

Part 3

SEDI-APP-04

No mandatory enrollment

ADMN

Part 3

SEDI-APP-05

Three eligibility criteria

AUTO

Part 3

SEDI-APP-06

Data minimization in application

EXPT

Part 3

SEDI-APP-07

Enumerated data collection fields

EXPT

Part 3

SEDI-IDP-01

Follow accepted proofing standard

EXPT

Part 3

SEDI-IDP-02

Risk-commensurate proofing

EXPT

Part 3

SEDI-IDP-03

Privacy-consistent proofing

EXPT

Part 3

SEDI-IDP-04

Four verified assertions

AUTO

Part 3

SEDI-IDP-05

Sufficient for age assurance reliance

EXPT

Part 3

SEDI-IDP-06

Online and offline suitability

EXPT

Part 3

SEDI-IDP-07

Point-in-time endorsement

AUTO

Part 3

SEDI-IDP-08

Independence from physical ID system

AUTO

Part 3

SEDI-IDP-09

No physical document surrender

ADMN

Part 3

SEDI-IDP-10

Multiple proofing methods

EXPT

Part 3

SEDI-IDP-11

Proofing entity authorization

ADMN

Part 3

Duty of Loyalty

     

SEDI-LOY-01

No conflicting practices

EXPT

Part 7

SEDI-LOY-02

No exploitation of individuals

ADMN

Part 7

SEDI-LOY-03

No disproportionate risk

EXPT

Part 7

SEDI-LOY-04

No detriment or harm

ADMN

Part 7

Enforcement

     

SEDI-ENF-01

Complaint submission mechanism

EXPT

Part 8

SEDI-ENF-02

Attorney general enforcement support

ADMN

Part 8

SEDI-ENF-03

Legislative audit

EXPT

Part 8

SEDI-ENF-04

Anti-surveillance architectural proof

EXPT

Part 8

Cross-Cutting

     

SEDI-CRY-01

Non-callback signature verification

AUTO

Part 9

SEDI-CRY-02

Holder-controlled key binding

AUTO

Part 9

SEDI-CRY-03

Selective disclosure and predicate proofs

AUTO

Part 9

SEDI-CRY-04

Open, royalty-free algorithms

AUTO

Part 9

SEDI-CRY-05

Cryptographic agility

EXPT

Part 9

SEDI-PRV-01

Protocol-level unlinkability

AUTO

Part 9

SEDI-PRV-02

Leak-resistant predicate evaluation

AUTO

Part 9

SEDI-PRV-03

Architectural anti-surveillance

EXPT

Part 9

SEDI-PRV-04

Lifecycle data minimization

EXPT

Part 9

SEDI-INT-01

Open standards for protocols and APIs

AUTO

Part 9

SEDI-INT-02

Common format across presentation modes

AUTO

Part 9

SEDI-INT-03

Wallet portability

AUTO

Part 9

SEDI-INT-04

No privacy-degrading fallback

EXPT

Part 9

SEDI-KMS-01

Key lifecycle policy

ADMN

Part 9

SEDI-KMS-02

Key generation ceremonies

ADMN

Part 9

SEDI-KMS-03

Hardware security modules

EXPT

Part 9

SEDI-KMS-04

Key rotation

AUTO

Part 9

SEDI-KMS-05

Key compromise response

ADMN

Part 9

SEDI-ORG-01

Access management

EXPT

Part 9

SEDI-ORG-02

Personnel security

ADMN

Part 9

SEDI-ORG-03

Vulnerability management

EXPT

Part 9

SEDI-ORG-04

Logging and monitoring

AUTO

Part 9

SEDI-ORG-05

Incident response

ADMN

Part 9

SEDI-ORG-06

Third-party compliance

EXPT

Part 9

SEDI-ORG-07

Change management

ADMN

Part 9

4.3 Holders / Individuals

Statutory authority: Utah Code §§ 63A-20-10163A-20-302

A holder is the individual whose identity attributes are contained in the SEDI, or a digital guardian acting on the individual's behalf (Utah Code § 63A-20-201(9)). The holder is the sovereign actor in the ecosystem: they control their personal digital identifier, choose their wallet, decide what to disclose, and consent to each presentation.

Rights applicable to this role:

Holders are rights-bearers under the Digital Identity Bill of Rights (Utah Code § 63A-20-101), not obligation-bearers. All SEDI-BOR requirements protect holder rights. See Utah Code § 63A-20-101 for the complete list.

4.4 Digital Wallet Providers

Statutory authority: Utah Code § 63A-20-401

A digital wallet provider creates, develops, maintains, and makes available the software or hardware that securely stores and presents a SEDI. Multiple wallet providers may exist simultaneously. Holders choose their wallet (Utah Code § 63A-20-301(1)(f)), and wallets must be interoperable via open standards.

Obligations applicable to this role:

Req ID

Short Description

Control

Source

Bill of Rights

     

SEDI-BOR-02

Right to management and control

AUTO

Part 1

SEDI-BOR-08

Right to choose disclosed attributes

AUTO

Part 1

SEDI-BOR-10

Right to freedom from surveillance

AUTO

Part 1

SEDI Core

     

SEDI-SDI-03

Cross-context correlation protections

AUTO

Part 3

SEDI-SDI-06

Online and offline presentation

AUTO

Part 3

SEDI-SDI-07

Selective disclosure

AUTO

Part 3

SEDI-SDI-08

Age verification without disclosure

AUTO

Part 3

SEDI-SDI-09

Wallet choice

AUTO

Part 3

SEDI-SDI-10

Usability

EXPT

Part 3

Wallet Provider

     

SEDI-WAL-01

Identity protection safeguards

AUTO

Part 4

SEDI-WAL-02

Secure attribute processing

AUTO

Part 4

SEDI-WAL-03

Technological compliance

EXPT

Part 4

SEDI-WAL-04

Tamper resistance

AUTO

Part 4

SEDI-WAL-05

Online and offline presentation

AUTO

Part 4

SEDI-WAL-06

Secure presentation log

AUTO

Part 4

SEDI-WAL-07

Selective disclosure

AUTO

Part 4

SEDI-WAL-08

Age predicate proof

AUTO

Part 4

SEDI-WAL-09

Guardian presentation

AUTO

Part 4

SEDI-WAL-10

Attribute processing limitation

AUTO

Part 4

SEDI-WAL-11

Conspicuous notice

EXPT

Part 4

SEDI-WAL-12

Per-transaction consent

AUTO

Part 4

SEDI-WAL-13

Primary purpose limitation

EXPT

Part 4

SEDI-WAL-14

No unauthorized retention or sharing

EXPT

Part 4

SEDI-WAL-15

Utah data protection law compliance

ADMN

Part 4

Duty of Loyalty

     

SEDI-LOY-01

No conflicting practices

EXPT

Part 7

SEDI-LOY-02

No exploitation of individuals

ADMN

Part 7

SEDI-LOY-03

No disproportionate risk

EXPT

Part 7

SEDI-LOY-04

No detriment or harm

ADMN

Part 7

Processing Restrictions

     

SEDI-PRC-01

Purpose-limited record processing

AUTO

Part 7

Enforcement

     

SEDI-ENF-02

Attorney general enforcement support

ADMN

Part 8

Cross-Cutting

     

SEDI-CRY-02

Holder-controlled key binding

AUTO

Part 9

SEDI-CRY-03

Selective disclosure and predicate proofs

AUTO

Part 9

SEDI-PRV-01

Protocol-level unlinkability

AUTO

Part 9

SEDI-PRV-02

Leak-resistant predicate evaluation

AUTO

Part 9

SEDI-INT-02

Common format across presentation modes

AUTO

Part 9

SEDI-INT-03

Wallet portability

AUTO

Part 9

SEDI-INT-04

No privacy-degrading fallback

EXPT

Part 9

4.5 Verifiers

Statutory authority: Utah Code § 63A-20-501

A verifier performs cryptographic verification of a SEDI: confirming the Department's signature, the credential's integrity, and the holder's proof of possession. The verifier role is technically specialized and may be a distinct entity from the relying party.

Obligations applicable to this role:

Req ID

Short Description

Control

Source

Bill of Rights

     

SEDI-BOR-08

Right to choose disclosed attributes

AUTO

Part 1

SEDI-BOR-11

Right to not surrender device

AUTO

Part 1

SEDI Core

     

SEDI-SDI-01

Compromise detection

AUTO

Part 3

SEDI-SDI-04

Authenticity and integrity

AUTO

Part 3

SEDI-SDI-06

Online and offline presentation

AUTO

Part 3

Verifier

     

SEDI-VER-01

Identity protection safeguards

AUTO

Part 5

SEDI-VER-02

Technological compliance

EXPT

Part 5

SEDI-VER-03

Secure attribute processing

AUTO

Part 5

SEDI-VER-04

Minimum attribute processing

AUTO

Part 5

SEDI-VER-05

Accept guardian presentations

AUTO

Part 5

SEDI-VER-06

Four-condition processing gate

AUTO

Part 5

SEDI-VER-07

No device surrender

AUTO

Part 5

SEDI-VER-08

Utah data protection law compliance

ADMN

Part 5

Duty of Loyalty

     

SEDI-LOY-01

No conflicting practices

EXPT

Part 7

SEDI-LOY-02

No exploitation of individuals

ADMN

Part 7

SEDI-LOY-03

No disproportionate risk

EXPT

Part 7

SEDI-LOY-04

No detriment or harm

ADMN

Part 7

Processing Restrictions

     

SEDI-PRC-01

Purpose-limited record processing

AUTO

Part 7

SEDI-PRC-02

Primary purpose limitation

AUTO

Part 7

SEDI-PRC-03

Notice and consent for secondary use

AUTO

Part 7

Enforcement

     

SEDI-ENF-02

Attorney general enforcement support

ADMN

Part 8

Cross-Cutting

     

SEDI-CRY-01

Non-callback signature verification

AUTO

Part 9

SEDI-INT-02

Common format across presentation modes

AUTO

Part 9

SEDI-INT-04

No privacy-degrading fallback

EXPT

Part 9

4.6 Relying Parties

Statutory authority: Utah Code § 63A-20-601

A relying party consumes the verifier's output to make a trust decision. It relies on the verified assertion of identity or identity attributes. A relying party may accept a SEDI as proof of identity unless a different method is required by law (Utah Code § 63A-20-601(4)).

Obligations applicable to this role:

Req ID

Short Description

Control

Source

Bill of Rights

     

SEDI-BOR-09

Right to service regardless of format

ADMN

Part 1

SEDI-BOR-11

Right to not surrender device

AUTO

Part 1

Verifier

     

SEDI-VER-04

Minimum attribute processing

AUTO

Part 5

Relying Party

     

SEDI-RPY-01

Identity protection safeguards

AUTO

Part 6

SEDI-RPY-02

Technological compliance

EXPT

Part 6

SEDI-RPY-03

Secure attribute processing

AUTO

Part 6

SEDI-RPY-04

Minimum attribute processing

EXPT

Part 6

SEDI-RPY-05

Accept guardian presentations

AUTO

Part 6

SEDI-RPY-06

Four-condition processing gate

AUTO

Part 6

SEDI-RPY-07

No device surrender

AUTO

Part 6

SEDI-RPY-08

Permissive SEDI acceptance

ADMN

Part 6

SEDI-RPY-09

Utah data protection law compliance

ADMN

Part 6

Duty of Loyalty

     

SEDI-LOY-01

No conflicting practices

EXPT

Part 7

SEDI-LOY-02

No exploitation of individuals

ADMN

Part 7

SEDI-LOY-03

No disproportionate risk

EXPT

Part 7

SEDI-LOY-04

No detriment or harm

ADMN

Part 7

Processing Restrictions

     

SEDI-PRC-01

Purpose-limited record processing

AUTO

Part 7

SEDI-PRC-02

Primary purpose limitation

AUTO

Part 7

SEDI-PRC-03

Notice and consent for secondary use

AUTO

Part 7

Enforcement

     

SEDI-ENF-02

Attorney general enforcement support

ADMN

Part 8

4.7 Identity Proofing Entities

Statutory authority: Utah Code §§ 63A-20-201(13)63A-20-303

An identity proofing entity is authorized by the Department to conduct identity proofing for the purpose of issuing a SEDI. This role enables the Department to delegate proofing to qualified third parties (e.g., existing government agencies, authorized private entities) while retaining validation authority (Utah Code § 63A-20-301(2)(a)).

Obligations applicable to this role:

Req ID

Short Description

Control

Source

SEDI-BOR-05

Right to endorsement on uniform standards

AUTO

Part 1

SEDI-SDI-11

Identity proofing validation

EXPT

Part 3

SEDI-APP-05

Three eligibility criteria

AUTO

Part 3

SEDI-IDP-01

Follow accepted proofing standard

EXPT

Part 3

SEDI-IDP-03

Privacy-consistent proofing

EXPT

Part 3

SEDI-IDP-04

Four verified assertions

AUTO

Part 3

4.8 Governmental Entities

Statutory authority: Utah Code § 63A-20-304

Governmental entities that accept digital identity must, within statutory timelines, also accept SEDI. They are bound by non-discrimination requirements (no benefit for digital over physical) and the prohibition on device surrender.

Obligations applicable to this role:

Req ID

Short Description

Control

Source

SEDI-BOR-03

Right to physical identity

ADMN

Part 1

SEDI-BOR-04

Right to not be compelled to use digital

ADMN

Part 1

SEDI-BOR-09

Right to service regardless of format

ADMN

Part 1

SEDI-BOR-11

Right to not surrender device

AUTO

Part 1

SEDI-APP-04

No mandatory enrollment

ADMN

Part 3

SEDI-GOV-01

No material benefit for SEDI use

ADMN

Part 3

SEDI-GOV-02

No service withholding for physical ID

ADMN

Part 3

SEDI-GOV-03

No device surrender

AUTO

Part 3

SEDI-GOV-04

New systems must accept SEDI

EXPT

Part 3

SEDI-GOV-05

Technical infeasibility exemption

ADMN

Part 3

4.9 Health Care Providers

Statutory authority: Utah Code § 63A-20-305

Health care providers receiving at least $10,000,000 per year in public funding that already accept digital identity must accept SEDI within two years of first issuance, subject to technical feasibility exemptions.

Obligations applicable to this role:

Req ID

Short Description

Control

Source

SEDI-BOR-09

Right to service regardless of format

ADMN

Part 1

SEDI-GOV-06

Health care provider SEDI acceptance

EXPT

Part 3

SEDI-GOV-07

Health care infeasibility exemption

ADMN

Part 3

4.10 Digital Guardians

Statutory authority: Utah Code §§ 63A-20-201(3)63A-20-302(2)-(3)

A digital guardian acts on behalf of a minor, incapacitated person, or an individual who has designated a representative. The guardian may apply for, manage, and present a SEDI on the individual's behalf. This role requires a delegation mechanism in the credential system.

Obligations applicable to this role:

Req ID

Short Description

Control

Source

SEDI-LOY-01

No conflicting practices

EXPT

Part 7

SEDI-LOY-02

No exploitation of individuals

ADMN

Part 7

SEDI-LOY-03

No disproportionate risk

EXPT

Part 7

SEDI-LOY-04

No detriment or harm

ADMN

Part 7

4.11 Data Privacy Ombudsperson

Statutory authority: Section Utah Code §§ 63A-19-501 , 63A-20-801

The data privacy ombudsperson receives and reviews complaints alleging violations of Chapter Utah Code Title 63A, Chapter -20 by any ecosystem participant, and may refer complaints to the attorney general.

Obligations applicable to this role:

Req ID

Short Description

Control

Source

SEDI-ENF-01

Complaint submission mechanism

EXPT

Part 8

4.12 Attorney General

Statutory authority: Utah Code § 63A-20-801(4)

The attorney general has enforcement authority, including civil investigative demands and civil actions for injunctive relief, declaratory relief, damages, restitution, and disgorgement.

Obligations applicable to this role:

Req ID

Short Description

Control

Source

SEDI-ENF-02

Attorney general enforcement support

ADMN

Part 8