Skip to content

Annex E: Role-Obligation Matrix

Cross-reference between roles and requirements.

Req ID Description Ctrl Dept WAL VER RP IPE GOV HCP DG DPO AG LAG
BOR-01 Identity is innate and inalienable EXPT X
BOR-02 Right to management and control EXPT X X
BOR-03 Right to physical identity ADMN X X
BOR-04 Right to not be compelled to use digital ADMN X X
BOR-05 Right to endorsement on uniform standard EXPT X X
BOR-06 Right to legislatively established stand ADMN X
BOR-07 Right to transparency EXPT X
BOR-08 Right to choose disclosed attributes AUTO X X X
BOR-09 Right to service regardless of format ADMN X X X
BOR-10 Right to freedom from surveillance AUTO X X
BOR-11 Right to not surrender device AUTO X X X
PRG-01 SEDI issuance compliance EXPT X
PRG-02 Publish technical standards EXPT X
PRG-03 Data governance standards EXPT X
PRG-04 45-day public comment period ADMN X
PRG-05 Response to public comments ADMN X
PRG-06 Fee structure publication ADMN X
PRG-07 Annual program reporting ADMN X
PRG-08 Program manager qualifications ADMN X
PRG-09 Interagency coordination ADMN X
PRG-10 Use case development ADMN X
PRG-11 Coordination standards and guidance ADMN X
SDI-01 Compromise detection AUTO X X
SDI-02 Recovery mechanisms EXPT X
SDI-03 Cross-context correlation protections AUTO X X
SDI-04 Authenticity and integrity AUTO X X
SDI-05 Interoperability EXPT X
SDI-06 Online and offline presentation AUTO X X X
SDI-07 Selective disclosure AUTO X X
SDI-08 Age verification without disclosure AUTO X X
SDI-09 Wallet choice AUTO X X
SDI-10 Usability EXPT X X
SDI-11 Identity proofing validation EXPT X X
SDI-12 Technological compliance mandate EXPT X
SDI-13 State data center requirement EXPT X
SDI-14 Data center best practices EXPT X
SDI-15 Open standards mandate AUTO X
SDI-16 Endorsed attribute set AUTO X
SDI-17 Anti-surveillance AUTO X
SDI-18 Purpose limitation AUTO X
SDI-19 Individual authorization AUTO X
SDI-20 Retention limitation AUTO X
SDI-21 In-state data storage EXPT X
SDI-22 Disclosure restrictions AUTO X
SDI-23 Revocation constraints AUTO X
SDI-24 Breach reporting EXPT X
APP-01 Age and emancipation eligibility AUTO X
APP-02 Guardian consent for minors AUTO X
APP-03 Guardian-initiated applications AUTO X
APP-04 No mandatory enrollment ADMN X X
APP-05 Three eligibility criteria AUTO X X
APP-06 Data minimization in application EXPT X
APP-07 Enumerated data collection fields EXPT X
IDP-01 Follow accepted proofing standard EXPT X X
IDP-02 Risk-commensurate proofing EXPT X
IDP-03 Privacy-consistent proofing EXPT X X
IDP-04 Four verified assertions AUTO X X
IDP-05 Sufficient for age assurance reliance EXPT X
IDP-06 Online and offline suitability EXPT X
IDP-07 Point-in-time endorsement AUTO X
APP-08 Fraud prohibition ADMN X
IDP-08 Independence from physical ID system AUTO X
IDP-09 No physical document surrender ADMN X
IDP-10 Multiple proofing methods EXPT X
IDP-11 Proofing entity authorization ADMN X
GOV-01 No material benefit for SEDI use ADMN X
GOV-02 No service withholding for physical ID ADMN X
GOV-03 No device surrender AUTO X
GOV-04 New systems must accept SEDI EXPT X
GOV-05 Technical infeasibility exemption ADMN X
GOV-06 Health care provider SEDI acceptance EXPT X
GOV-07 Health care infeasibility exemption ADMN X
WAL-01 Identity protection safeguards AUTO X
WAL-02 Secure attribute processing AUTO X
WAL-03 Technological compliance EXPT X
WAL-04 Tamper resistance AUTO X
WAL-05 Online and offline presentation AUTO X
WAL-06 Secure presentation log AUTO X
WAL-07 Selective disclosure AUTO X
WAL-08 Age predicate proof AUTO X
WAL-09 Guardian presentation AUTO X
WAL-10 Attribute processing limitation AUTO X
WAL-11 Conspicuous notice EXPT X
WAL-12 Per-transaction consent AUTO X
WAL-13 Primary purpose limitation EXPT X
WAL-14 No unauthorized retention or sharing EXPT X
WAL-15 Utah data protection law compliance ADMN X
VER-01 Identity protection safeguards AUTO X
VER-02 Technological compliance EXPT X
VER-03 Secure attribute processing AUTO X
VER-04 Minimum attribute processing AUTO X X
VER-05 Accept guardian presentations AUTO X
VER-06 Four-condition processing gate AUTO X
VER-07 No device surrender AUTO X
VER-08 Utah data protection law compliance ADMN X
RPY-01 Identity protection safeguards AUTO X
RPY-02 Technological compliance EXPT X
RPY-03 Secure attribute processing AUTO X
RPY-04 Minimum attribute processing EXPT X
RPY-05 Accept guardian presentations AUTO X
RPY-06 Four-condition processing gate AUTO X
RPY-07 No device surrender AUTO X
RPY-08 Permissive SEDI acceptance ADMN X
RPY-09 Utah data protection law compliance ADMN X
LOY-01 No conflicting practices EXPT X X X X X
LOY-02 No exploitation of individuals ADMN X X X X X
LOY-03 No disproportionate risk EXPT X X X X X X X X X X X
LOY-04 No detriment ADMN X X X X X X X X X X X
LOY-05 No harm ADMN X X X X X X X X X X X
PRC-01 Purpose-limited record processing AUTO X X X
PRC-02 Primary purpose limitation AUTO X X
PRC-03 Notice and consent for secondary use AUTO X X
ENF-01 Complaint submission mechanism EXPT X X
ENF-02 Attorney general enforcement support ADMN X X X X X X X X X X X
ENF-03 Legislative audit EXPT X
ENF-04 Anti-surveillance architectural proof EXPT X
ENF-05 Audit report deadline ADMN X
CRY-01 Non-callback signature verification AUTO X X
CRY-02 Holder-controlled key binding AUTO X X
CRY-03 Selective disclosure and predicate proof AUTO X X
CRY-04 Open, royalty-free algorithms AUTO X
CRY-05 Cryptographic agility EXPT X
PRV-01 Protocol-level unlinkability AUTO X X
PRV-02 Leak-resistant predicate evaluation AUTO X X
PRV-03 Architectural anti-surveillance EXPT X
PRV-04 Lifecycle data minimization EXPT X X X X X
INT-01 Open standards for protocols and APIs AUTO X
INT-02 Common format across presentation modes AUTO X X X
INT-03 Wallet portability AUTO X X
INT-04 No privacy-degrading fallback EXPT X X X
KMS-01 Key lifecycle policy ADMN X
KMS-02 Key generation ceremonies ADMN X
KMS-03 Hardware security modules EXPT X
KMS-04 Key rotation AUTO X
KMS-05 Key compromise response ADMN X
ORG-01 Access management EXPT X
ORG-02 Personnel security ADMN X
ORG-03 Vulnerability management EXPT X
ORG-04 Logging and monitoring AUTO X
ORG-05 Incident response ADMN X
ORG-06 Third-party compliance EXPT X
ORG-07 Change management ADMN X

Obligation Counts

Role Count
Department 97
Wallet Providers 39
Verifiers 26
Relying Parties 22
Identity Proofing Entities 11
Governmental Entities 14
Health Care Providers 7
Digital Guardians 6
Data Privacy Ombudsperson 5
Attorney General 4
Legislative Auditor General 5

Total: 142 requirements