Annex G: Roles and Actors
4.1 Overview of the SEDI Ecosystem
The SEDI ecosystem comprises the following roles, each with distinct statutory obligations. An entity may serve multiple roles simultaneously (e.g., a governmental entity may also be a relying party).
4.2 Department / Program
Statutory authority: Utah Code §§ 63A-20-202, 203
The Department of Government Operations operates the SEDI program. In identity ecosystem terms, the Department is the issuer: the entity that endorses (digitally signs) the holder's identity attributes, binding them to the holder's personal digital identifier. The Department also sets standards, approves conformance profiles, and operates the issuance and revocation infrastructure.
Key constraint: The Department's role ends at issuance. The statute prohibits the Department from monitoring, surveilling, or tracking presentations (Utah Code § 63A-20-301(3)).
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
Bill of Rights |
|||
|
Identity is innate and inalienable |
AUTO |
Part 1 |
|
|
Right to management and control |
AUTO |
Part 1 |
|
|
Right to physical identity |
ADMN |
Part 1 |
|
|
Right to not be compelled to use digital |
ADMN |
Part 1 |
|
|
Right to endorsement on uniform standards |
AUTO |
Part 1 |
|
|
Right to legislatively established standards |
ADMN |
Part 1 |
|
|
Right to transparency |
EXPT |
Part 1 |
|
|
Right to choose disclosed attributes |
AUTO |
Part 1 |
|
|
Right to freedom from surveillance |
AUTO |
Part 1 |
|
|
Program |
|||
|
SEDI issuance compliance |
EXPT |
Part 2 |
|
|
Publish technical standards |
EXPT |
Part 2 |
|
|
Data governance standards |
EXPT |
Part 2 |
|
|
45-day public comment period |
ADMN |
Part 2 |
|
|
Response to public comments |
ADMN |
Part 2 |
|
|
Fee structure publication |
ADMN |
Part 2 |
|
|
Annual program reporting |
ADMN |
Part 2 |
|
|
Program manager qualifications |
ADMN |
Part 2 |
|
|
SEDI Core |
|||
|
Compromise detection |
AUTO |
Part 3 |
|
|
Recovery mechanisms |
EXPT |
Part 3 |
|
|
Cross-context correlation protections |
AUTO |
Part 3 |
|
|
Authenticity and integrity |
AUTO |
Part 3 |
|
|
Interoperability |
EXPT |
Part 3 |
|
|
Online and offline presentation |
AUTO |
Part 3 |
|
|
Selective disclosure |
AUTO |
Part 3 |
|
|
Age verification without disclosure |
AUTO |
Part 3 |
|
|
Wallet choice |
AUTO |
Part 3 |
|
|
Usability |
EXPT |
Part 3 |
|
|
Identity proofing validation |
EXPT |
Part 3 |
|
|
Technological compliance mandate |
EXPT |
Part 3 |
|
|
State data center requirement |
EXPT |
Part 3 |
|
|
Data center best practices |
EXPT |
Part 3 |
|
|
Open standards mandate |
AUTO |
Part 3 |
|
|
Endorsed attribute set |
AUTO |
Part 3 |
|
|
Anti-surveillance |
AUTO |
Part 3 |
|
|
Purpose limitation |
AUTO |
Part 3 |
|
|
Retention limitation |
AUTO |
Part 3 |
|
|
In-state data storage |
EXPT |
Part 3 |
|
|
Disclosure restrictions |
AUTO |
Part 3 |
|
|
Revocation constraints |
AUTO |
Part 3 |
|
|
Breach reporting |
EXPT |
Part 3 |
|
|
Application & Proofing |
|||
|
Age and emancipation eligibility |
AUTO |
Part 3 |
|
|
Guardian consent for minors |
AUTO |
Part 3 |
|
|
Guardian-initiated applications |
AUTO |
Part 3 |
|
|
No mandatory enrollment |
ADMN |
Part 3 |
|
|
Three eligibility criteria |
AUTO |
Part 3 |
|
|
Data minimization in application |
EXPT |
Part 3 |
|
|
Enumerated data collection fields |
EXPT |
Part 3 |
|
|
Follow accepted proofing standard |
EXPT |
Part 3 |
|
|
Risk-commensurate proofing |
EXPT |
Part 3 |
|
|
Privacy-consistent proofing |
EXPT |
Part 3 |
|
|
Four verified assertions |
AUTO |
Part 3 |
|
|
Sufficient for age assurance reliance |
EXPT |
Part 3 |
|
|
Online and offline suitability |
EXPT |
Part 3 |
|
|
Point-in-time endorsement |
AUTO |
Part 3 |
|
|
Independence from physical ID system |
AUTO |
Part 3 |
|
|
No physical document surrender |
ADMN |
Part 3 |
|
|
Multiple proofing methods |
EXPT |
Part 3 |
|
|
Proofing entity authorization |
ADMN |
Part 3 |
|
|
Duty of Loyalty |
|||
|
No conflicting practices |
EXPT |
Part 7 |
|
|
No exploitation of individuals |
ADMN |
Part 7 |
|
|
No disproportionate risk |
EXPT |
Part 7 |
|
|
No detriment or harm |
ADMN |
Part 7 |
|
|
Enforcement |
|||
|
Complaint submission mechanism |
EXPT |
Part 8 |
|
|
Attorney general enforcement support |
ADMN |
Part 8 |
|
|
Legislative audit |
EXPT |
Part 8 |
|
|
Anti-surveillance architectural proof |
EXPT |
Part 8 |
|
|
Cross-Cutting |
|||
|
Non-callback signature verification |
AUTO |
Part 9 |
|
|
Holder-controlled key binding |
AUTO |
Part 9 |
|
|
Selective disclosure and predicate proofs |
AUTO |
Part 9 |
|
|
Open, royalty-free algorithms |
AUTO |
Part 9 |
|
|
Cryptographic agility |
EXPT |
Part 9 |
|
|
Protocol-level unlinkability |
AUTO |
Part 9 |
|
|
Leak-resistant predicate evaluation |
AUTO |
Part 9 |
|
|
Architectural anti-surveillance |
EXPT |
Part 9 |
|
|
Lifecycle data minimization |
EXPT |
Part 9 |
|
|
Open standards for protocols and APIs |
AUTO |
Part 9 |
|
|
Common format across presentation modes |
AUTO |
Part 9 |
|
|
Wallet portability |
AUTO |
Part 9 |
|
|
No privacy-degrading fallback |
EXPT |
Part 9 |
|
|
Key lifecycle policy |
ADMN |
Part 9 |
|
|
Key generation ceremonies |
ADMN |
Part 9 |
|
|
Hardware security modules |
EXPT |
Part 9 |
|
|
Key rotation |
AUTO |
Part 9 |
|
|
Key compromise response |
ADMN |
Part 9 |
|
|
Access management |
EXPT |
Part 9 |
|
|
Personnel security |
ADMN |
Part 9 |
|
|
Vulnerability management |
EXPT |
Part 9 |
|
|
Logging and monitoring |
AUTO |
Part 9 |
|
|
Incident response |
ADMN |
Part 9 |
|
|
Third-party compliance |
EXPT |
Part 9 |
|
|
Change management |
ADMN |
Part 9 |
4.3 Holders / Individuals
Statutory authority: Utah Code §§ 63A-20-101, 63A-20-302
A holder is the individual whose identity attributes are contained in the SEDI, or a digital guardian acting on the individual's behalf (Utah Code § 63A-20-201(9)). The holder is the sovereign actor in the ecosystem: they control their personal digital identifier, choose their wallet, decide what to disclose, and consent to each presentation.
Rights applicable to this role:
Holders are rights-bearers under the Digital Identity Bill of Rights (Utah Code § 63A-20-101), not obligation-bearers. All SEDI-BOR requirements protect holder rights. See Utah Code § 63A-20-101 for the complete list.
4.4 Digital Wallet Providers
Statutory authority: Utah Code § 63A-20-401
A digital wallet provider creates, develops, maintains, and makes available the software or hardware that securely stores and presents a SEDI. Multiple wallet providers may exist simultaneously. Holders choose their wallet (Utah Code § 63A-20-301(1)(f)), and wallets must be interoperable via open standards.
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
Bill of Rights |
|||
|
Right to management and control |
AUTO |
Part 1 |
|
|
Right to choose disclosed attributes |
AUTO |
Part 1 |
|
|
Right to freedom from surveillance |
AUTO |
Part 1 |
|
|
SEDI Core |
|||
|
Cross-context correlation protections |
AUTO |
Part 3 |
|
|
Online and offline presentation |
AUTO |
Part 3 |
|
|
Selective disclosure |
AUTO |
Part 3 |
|
|
Age verification without disclosure |
AUTO |
Part 3 |
|
|
Wallet choice |
AUTO |
Part 3 |
|
|
Usability |
EXPT |
Part 3 |
|
|
Wallet Provider |
|||
|
Identity protection safeguards |
AUTO |
Part 4 |
|
|
Secure attribute processing |
AUTO |
Part 4 |
|
|
Technological compliance |
EXPT |
Part 4 |
|
|
Tamper resistance |
AUTO |
Part 4 |
|
|
Online and offline presentation |
AUTO |
Part 4 |
|
|
Secure presentation log |
AUTO |
Part 4 |
|
|
Selective disclosure |
AUTO |
Part 4 |
|
|
Age predicate proof |
AUTO |
Part 4 |
|
|
Guardian presentation |
AUTO |
Part 4 |
|
|
Attribute processing limitation |
AUTO |
Part 4 |
|
|
Conspicuous notice |
EXPT |
Part 4 |
|
|
Per-transaction consent |
AUTO |
Part 4 |
|
|
Primary purpose limitation |
EXPT |
Part 4 |
|
|
No unauthorized retention or sharing |
EXPT |
Part 4 |
|
|
Utah data protection law compliance |
ADMN |
Part 4 |
|
|
Duty of Loyalty |
|||
|
No conflicting practices |
EXPT |
Part 7 |
|
|
No exploitation of individuals |
ADMN |
Part 7 |
|
|
No disproportionate risk |
EXPT |
Part 7 |
|
|
No detriment or harm |
ADMN |
Part 7 |
|
|
Processing Restrictions |
|||
|
Purpose-limited record processing |
AUTO |
Part 7 |
|
|
Enforcement |
|||
|
Attorney general enforcement support |
ADMN |
Part 8 |
|
|
Cross-Cutting |
|||
|
Holder-controlled key binding |
AUTO |
Part 9 |
|
|
Selective disclosure and predicate proofs |
AUTO |
Part 9 |
|
|
Protocol-level unlinkability |
AUTO |
Part 9 |
|
|
Leak-resistant predicate evaluation |
AUTO |
Part 9 |
|
|
Common format across presentation modes |
AUTO |
Part 9 |
|
|
Wallet portability |
AUTO |
Part 9 |
|
|
No privacy-degrading fallback |
EXPT |
Part 9 |
4.5 Verifiers
Statutory authority: Utah Code § 63A-20-501
A verifier performs cryptographic verification of a SEDI: confirming the Department's signature, the credential's integrity, and the holder's proof of possession. The verifier role is technically specialized and may be a distinct entity from the relying party.
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
Bill of Rights |
|||
|
Right to choose disclosed attributes |
AUTO |
Part 1 |
|
|
Right to not surrender device |
AUTO |
Part 1 |
|
|
SEDI Core |
|||
|
Compromise detection |
AUTO |
Part 3 |
|
|
Authenticity and integrity |
AUTO |
Part 3 |
|
|
Online and offline presentation |
AUTO |
Part 3 |
|
|
Verifier |
|||
|
Identity protection safeguards |
AUTO |
Part 5 |
|
|
Technological compliance |
EXPT |
Part 5 |
|
|
Secure attribute processing |
AUTO |
Part 5 |
|
|
Minimum attribute processing |
AUTO |
Part 5 |
|
|
Accept guardian presentations |
AUTO |
Part 5 |
|
|
Four-condition processing gate |
AUTO |
Part 5 |
|
|
No device surrender |
AUTO |
Part 5 |
|
|
Utah data protection law compliance |
ADMN |
Part 5 |
|
|
Duty of Loyalty |
|||
|
No conflicting practices |
EXPT |
Part 7 |
|
|
No exploitation of individuals |
ADMN |
Part 7 |
|
|
No disproportionate risk |
EXPT |
Part 7 |
|
|
No detriment or harm |
ADMN |
Part 7 |
|
|
Processing Restrictions |
|||
|
Purpose-limited record processing |
AUTO |
Part 7 |
|
|
Primary purpose limitation |
AUTO |
Part 7 |
|
|
Notice and consent for secondary use |
AUTO |
Part 7 |
|
|
Enforcement |
|||
|
Attorney general enforcement support |
ADMN |
Part 8 |
|
|
Cross-Cutting |
|||
|
Non-callback signature verification |
AUTO |
Part 9 |
|
|
Common format across presentation modes |
AUTO |
Part 9 |
|
|
No privacy-degrading fallback |
EXPT |
Part 9 |
4.6 Relying Parties
Statutory authority: Utah Code § 63A-20-601
A relying party consumes the verifier's output to make a trust decision. It relies on the verified assertion of identity or identity attributes. A relying party may accept a SEDI as proof of identity unless a different method is required by law (Utah Code § 63A-20-601(4)).
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
Bill of Rights |
|||
|
Right to service regardless of format |
ADMN |
Part 1 |
|
|
Right to not surrender device |
AUTO |
Part 1 |
|
|
Verifier |
|||
|
Minimum attribute processing |
AUTO |
Part 5 |
|
|
Relying Party |
|||
|
Identity protection safeguards |
AUTO |
Part 6 |
|
|
Technological compliance |
EXPT |
Part 6 |
|
|
Secure attribute processing |
AUTO |
Part 6 |
|
|
Minimum attribute processing |
EXPT |
Part 6 |
|
|
Accept guardian presentations |
AUTO |
Part 6 |
|
|
Four-condition processing gate |
AUTO |
Part 6 |
|
|
No device surrender |
AUTO |
Part 6 |
|
|
Permissive SEDI acceptance |
ADMN |
Part 6 |
|
|
Utah data protection law compliance |
ADMN |
Part 6 |
|
|
Duty of Loyalty |
|||
|
No conflicting practices |
EXPT |
Part 7 |
|
|
No exploitation of individuals |
ADMN |
Part 7 |
|
|
No disproportionate risk |
EXPT |
Part 7 |
|
|
No detriment or harm |
ADMN |
Part 7 |
|
|
Processing Restrictions |
|||
|
Purpose-limited record processing |
AUTO |
Part 7 |
|
|
Primary purpose limitation |
AUTO |
Part 7 |
|
|
Notice and consent for secondary use |
AUTO |
Part 7 |
|
|
Enforcement |
|||
|
Attorney general enforcement support |
ADMN |
Part 8 |
4.7 Identity Proofing Entities
Statutory authority: Utah Code §§ 63A-20-201(13), 63A-20-303
An identity proofing entity is authorized by the Department to conduct identity proofing for the purpose of issuing a SEDI. This role enables the Department to delegate proofing to qualified third parties (e.g., existing government agencies, authorized private entities) while retaining validation authority (Utah Code § 63A-20-301(2)(a)).
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
Right to endorsement on uniform standards |
AUTO |
Part 1 |
|
|
Identity proofing validation |
EXPT |
Part 3 |
|
|
Three eligibility criteria |
AUTO |
Part 3 |
|
|
Follow accepted proofing standard |
EXPT |
Part 3 |
|
|
Privacy-consistent proofing |
EXPT |
Part 3 |
|
|
Four verified assertions |
AUTO |
Part 3 |
4.8 Governmental Entities
Statutory authority: Utah Code § 63A-20-304
Governmental entities that accept digital identity must, within statutory timelines, also accept SEDI. They are bound by non-discrimination requirements (no benefit for digital over physical) and the prohibition on device surrender.
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
Right to physical identity |
ADMN |
Part 1 |
|
|
Right to not be compelled to use digital |
ADMN |
Part 1 |
|
|
Right to service regardless of format |
ADMN |
Part 1 |
|
|
Right to not surrender device |
AUTO |
Part 1 |
|
|
No mandatory enrollment |
ADMN |
Part 3 |
|
|
No material benefit for SEDI use |
ADMN |
Part 3 |
|
|
No service withholding for physical ID |
ADMN |
Part 3 |
|
|
No device surrender |
AUTO |
Part 3 |
|
|
New systems must accept SEDI |
EXPT |
Part 3 |
|
|
Technical infeasibility exemption |
ADMN |
Part 3 |
4.9 Health Care Providers
Statutory authority: Utah Code § 63A-20-305
Health care providers receiving at least $10,000,000 per year in public funding that already accept digital identity must accept SEDI within two years of first issuance, subject to technical feasibility exemptions.
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
Right to service regardless of format |
ADMN |
Part 1 |
|
|
Health care provider SEDI acceptance |
EXPT |
Part 3 |
|
|
Health care infeasibility exemption |
ADMN |
Part 3 |
4.10 Digital Guardians
Statutory authority: Utah Code §§ 63A-20-201(3), 63A-20-302(2)-(3)
A digital guardian acts on behalf of a minor, incapacitated person, or an individual who has designated a representative. The guardian may apply for, manage, and present a SEDI on the individual's behalf. This role requires a delegation mechanism in the credential system.
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
No conflicting practices |
EXPT |
Part 7 |
|
|
No exploitation of individuals |
ADMN |
Part 7 |
|
|
No disproportionate risk |
EXPT |
Part 7 |
|
|
No detriment or harm |
ADMN |
Part 7 |
4.11 Data Privacy Ombudsperson
Statutory authority: Section Utah Code §§ 63A-19-501 , 63A-20-801
The data privacy ombudsperson receives and reviews complaints alleging violations of Chapter Utah Code Title 63A, Chapter -20 by any ecosystem participant, and may refer complaints to the attorney general.
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
Complaint submission mechanism |
EXPT |
Part 8 |
4.12 Attorney General
Statutory authority: Utah Code § 63A-20-801(4)
The attorney general has enforcement authority, including civil investigative demands and civil actions for injunctive relief, declaratory relief, damages, restitution, and disgorgement.
Obligations applicable to this role:
|
Req ID |
Short Description |
Control |
Source |
|---|---|---|---|
|
Attorney general enforcement support |
ADMN |
Part 8 |