Annex E: Role-Obligation Matrix¶
Cross-reference between roles and requirements.
| Req ID | Description | Ctrl | Dept | WAL | VER | RP | IPE | GOV | HCP | DG | DPO | AG | LAG |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| BOR-01 | Identity is innate and inalienable | EXPT | X | ||||||||||
| BOR-02 | Right to management and control | EXPT | X | X | |||||||||
| BOR-03 | Right to physical identity | ADMN | X | X | |||||||||
| BOR-04 | Right to not be compelled to use digital | ADMN | X | X | |||||||||
| BOR-05 | Right to endorsement on uniform standard | EXPT | X | X | |||||||||
| BOR-06 | Right to legislatively established stand | ADMN | X | ||||||||||
| BOR-07 | Right to transparency | EXPT | X | ||||||||||
| BOR-08 | Right to choose disclosed attributes | AUTO | X | X | X | ||||||||
| BOR-09 | Right to service regardless of format | ADMN | X | X | X | ||||||||
| BOR-10 | Right to freedom from surveillance | AUTO | X | X | |||||||||
| BOR-11 | Right to not surrender device | AUTO | X | X | X | ||||||||
| PRG-01 | SEDI issuance compliance | EXPT | X | ||||||||||
| PRG-02 | Publish technical standards | EXPT | X | ||||||||||
| PRG-03 | Data governance standards | EXPT | X | ||||||||||
| PRG-04 | 45-day public comment period | ADMN | X | ||||||||||
| PRG-05 | Response to public comments | ADMN | X | ||||||||||
| PRG-06 | Fee structure publication | ADMN | X | ||||||||||
| PRG-07 | Annual program reporting | ADMN | X | ||||||||||
| PRG-08 | Program manager qualifications | ADMN | X | ||||||||||
| PRG-09 | Interagency coordination | ADMN | X | ||||||||||
| PRG-10 | Use case development | ADMN | X | ||||||||||
| PRG-11 | Coordination standards and guidance | ADMN | X | ||||||||||
| SDI-01 | Compromise detection | AUTO | X | X | |||||||||
| SDI-02 | Recovery mechanisms | EXPT | X | ||||||||||
| SDI-03 | Cross-context correlation protections | AUTO | X | X | |||||||||
| SDI-04 | Authenticity and integrity | AUTO | X | X | |||||||||
| SDI-05 | Interoperability | EXPT | X | ||||||||||
| SDI-06 | Online and offline presentation | AUTO | X | X | X | ||||||||
| SDI-07 | Selective disclosure | AUTO | X | X | |||||||||
| SDI-08 | Age verification without disclosure | AUTO | X | X | |||||||||
| SDI-09 | Wallet choice | AUTO | X | X | |||||||||
| SDI-10 | Usability | EXPT | X | X | |||||||||
| SDI-11 | Identity proofing validation | EXPT | X | X | |||||||||
| SDI-12 | Technological compliance mandate | EXPT | X | ||||||||||
| SDI-13 | State data center requirement | EXPT | X | ||||||||||
| SDI-14 | Data center best practices | EXPT | X | ||||||||||
| SDI-15 | Open standards mandate | AUTO | X | ||||||||||
| SDI-16 | Endorsed attribute set | AUTO | X | ||||||||||
| SDI-17 | Anti-surveillance | AUTO | X | ||||||||||
| SDI-18 | Purpose limitation | AUTO | X | ||||||||||
| SDI-19 | Individual authorization | AUTO | X | ||||||||||
| SDI-20 | Retention limitation | AUTO | X | ||||||||||
| SDI-21 | In-state data storage | EXPT | X | ||||||||||
| SDI-22 | Disclosure restrictions | AUTO | X | ||||||||||
| SDI-23 | Revocation constraints | AUTO | X | ||||||||||
| SDI-24 | Breach reporting | EXPT | X | ||||||||||
| APP-01 | Age and emancipation eligibility | AUTO | X | ||||||||||
| APP-02 | Guardian consent for minors | AUTO | X | ||||||||||
| APP-03 | Guardian-initiated applications | AUTO | X | ||||||||||
| APP-04 | No mandatory enrollment | ADMN | X | X | |||||||||
| APP-05 | Three eligibility criteria | AUTO | X | X | |||||||||
| APP-06 | Data minimization in application | EXPT | X | ||||||||||
| APP-07 | Enumerated data collection fields | EXPT | X | ||||||||||
| IDP-01 | Follow accepted proofing standard | EXPT | X | X | |||||||||
| IDP-02 | Risk-commensurate proofing | EXPT | X | ||||||||||
| IDP-03 | Privacy-consistent proofing | EXPT | X | X | |||||||||
| IDP-04 | Four verified assertions | AUTO | X | X | |||||||||
| IDP-05 | Sufficient for age assurance reliance | EXPT | X | ||||||||||
| IDP-06 | Online and offline suitability | EXPT | X | ||||||||||
| IDP-07 | Point-in-time endorsement | AUTO | X | ||||||||||
| APP-08 | Fraud prohibition | ADMN | X | ||||||||||
| IDP-08 | Independence from physical ID system | AUTO | X | ||||||||||
| IDP-09 | No physical document surrender | ADMN | X | ||||||||||
| IDP-10 | Multiple proofing methods | EXPT | X | ||||||||||
| IDP-11 | Proofing entity authorization | ADMN | X | ||||||||||
| GOV-01 | No material benefit for SEDI use | ADMN | X | ||||||||||
| GOV-02 | No service withholding for physical ID | ADMN | X | ||||||||||
| GOV-03 | No device surrender | AUTO | X | ||||||||||
| GOV-04 | New systems must accept SEDI | EXPT | X | ||||||||||
| GOV-05 | Technical infeasibility exemption | ADMN | X | ||||||||||
| GOV-06 | Health care provider SEDI acceptance | EXPT | X | ||||||||||
| GOV-07 | Health care infeasibility exemption | ADMN | X | ||||||||||
| WAL-01 | Identity protection safeguards | AUTO | X | ||||||||||
| WAL-02 | Secure attribute processing | AUTO | X | ||||||||||
| WAL-03 | Technological compliance | EXPT | X | ||||||||||
| WAL-04 | Tamper resistance | AUTO | X | ||||||||||
| WAL-05 | Online and offline presentation | AUTO | X | ||||||||||
| WAL-06 | Secure presentation log | AUTO | X | ||||||||||
| WAL-07 | Selective disclosure | AUTO | X | ||||||||||
| WAL-08 | Age predicate proof | AUTO | X | ||||||||||
| WAL-09 | Guardian presentation | AUTO | X | ||||||||||
| WAL-10 | Attribute processing limitation | AUTO | X | ||||||||||
| WAL-11 | Conspicuous notice | EXPT | X | ||||||||||
| WAL-12 | Per-transaction consent | AUTO | X | ||||||||||
| WAL-13 | Primary purpose limitation | EXPT | X | ||||||||||
| WAL-14 | No unauthorized retention or sharing | EXPT | X | ||||||||||
| WAL-15 | Utah data protection law compliance | ADMN | X | ||||||||||
| VER-01 | Identity protection safeguards | AUTO | X | ||||||||||
| VER-02 | Technological compliance | EXPT | X | ||||||||||
| VER-03 | Secure attribute processing | AUTO | X | ||||||||||
| VER-04 | Minimum attribute processing | AUTO | X | X | |||||||||
| VER-05 | Accept guardian presentations | AUTO | X | ||||||||||
| VER-06 | Four-condition processing gate | AUTO | X | ||||||||||
| VER-07 | No device surrender | AUTO | X | ||||||||||
| VER-08 | Utah data protection law compliance | ADMN | X | ||||||||||
| RPY-01 | Identity protection safeguards | AUTO | X | ||||||||||
| RPY-02 | Technological compliance | EXPT | X | ||||||||||
| RPY-03 | Secure attribute processing | AUTO | X | ||||||||||
| RPY-04 | Minimum attribute processing | EXPT | X | ||||||||||
| RPY-05 | Accept guardian presentations | AUTO | X | ||||||||||
| RPY-06 | Four-condition processing gate | AUTO | X | ||||||||||
| RPY-07 | No device surrender | AUTO | X | ||||||||||
| RPY-08 | Permissive SEDI acceptance | ADMN | X | ||||||||||
| RPY-09 | Utah data protection law compliance | ADMN | X | ||||||||||
| LOY-01 | No conflicting practices | EXPT | X | X | X | X | X | ||||||
| LOY-02 | No exploitation of individuals | ADMN | X | X | X | X | X | ||||||
| LOY-03 | No disproportionate risk | EXPT | X | X | X | X | X | X | X | X | X | X | X |
| LOY-04 | No detriment | ADMN | X | X | X | X | X | X | X | X | X | X | X |
| LOY-05 | No harm | ADMN | X | X | X | X | X | X | X | X | X | X | X |
| PRC-01 | Purpose-limited record processing | AUTO | X | X | X | ||||||||
| PRC-02 | Primary purpose limitation | AUTO | X | X | |||||||||
| PRC-03 | Notice and consent for secondary use | AUTO | X | X | |||||||||
| ENF-01 | Complaint submission mechanism | EXPT | X | X | |||||||||
| ENF-02 | Attorney general enforcement support | ADMN | X | X | X | X | X | X | X | X | X | X | X |
| ENF-03 | Legislative audit | EXPT | X | ||||||||||
| ENF-04 | Anti-surveillance architectural proof | EXPT | X | ||||||||||
| ENF-05 | Audit report deadline | ADMN | X | ||||||||||
| CRY-01 | Non-callback signature verification | AUTO | X | X | |||||||||
| CRY-02 | Holder-controlled key binding | AUTO | X | X | |||||||||
| CRY-03 | Selective disclosure and predicate proof | AUTO | X | X | |||||||||
| CRY-04 | Open, royalty-free algorithms | AUTO | X | ||||||||||
| CRY-05 | Cryptographic agility | EXPT | X | ||||||||||
| PRV-01 | Protocol-level unlinkability | AUTO | X | X | |||||||||
| PRV-02 | Leak-resistant predicate evaluation | AUTO | X | X | |||||||||
| PRV-03 | Architectural anti-surveillance | EXPT | X | ||||||||||
| PRV-04 | Lifecycle data minimization | EXPT | X | X | X | X | X | ||||||
| INT-01 | Open standards for protocols and APIs | AUTO | X | ||||||||||
| INT-02 | Common format across presentation modes | AUTO | X | X | X | ||||||||
| INT-03 | Wallet portability | AUTO | X | X | |||||||||
| INT-04 | No privacy-degrading fallback | EXPT | X | X | X | ||||||||
| KMS-01 | Key lifecycle policy | ADMN | X | ||||||||||
| KMS-02 | Key generation ceremonies | ADMN | X | ||||||||||
| KMS-03 | Hardware security modules | EXPT | X | ||||||||||
| KMS-04 | Key rotation | AUTO | X | ||||||||||
| KMS-05 | Key compromise response | ADMN | X | ||||||||||
| ORG-01 | Access management | EXPT | X | ||||||||||
| ORG-02 | Personnel security | ADMN | X | ||||||||||
| ORG-03 | Vulnerability management | EXPT | X | ||||||||||
| ORG-04 | Logging and monitoring | AUTO | X | ||||||||||
| ORG-05 | Incident response | ADMN | X | ||||||||||
| ORG-06 | Third-party compliance | EXPT | X | ||||||||||
| ORG-07 | Change management | ADMN | X |
Obligation Counts¶
| Role | Count |
|---|---|
| Department | 97 |
| Wallet Providers | 39 |
| Verifiers | 26 |
| Relying Parties | 22 |
| Identity Proofing Entities | 11 |
| Governmental Entities | 14 |
| Health Care Providers | 7 |
| Digital Guardians | 6 |
| Data Privacy Ombudsperson | 5 |
| Attorney General | 4 |
| Legislative Auditor General | 5 |
Total: 142 requirements