V0.1
Terminology and identity relationships
Use these terms consistently. An identifier or association is not authority.
The public glossary defines the roles and non-inferences. This chapter states the canonical relationships and cardinalities.
IP-ID-01 — Entity separation. Passport and Root Identity are distinct; every Passport has exactly one Root Identity. [ADRs 8A, 8I; domain-model.md, Normative relationships.]
IP-ID-02 — Membership cardinality. A Passport may govern many Subordinates; an active Subordinate has exactly one authoritative Passport at a time. [ADR 8C.]
IP-ID-03 — Account relationships. Account-to-Passport authorization relationships are explicit and may be many-to-many. Shared Account access does not create identity linkage. [ADR 8B.]
IP-ID-04 — Authentication separation. Authentication identifies a Principal in a trusted context. Account association, identity mapping, and operation authorization are distinct facts. [ADRs 7D, 8B; domain model and integration boundary.]
IP-ID-05 — Identifier privacy. Internal continuity identifiers must not become unavoidable public correlation identifiers; context-facing bindings and their rotation preserve private continuity while limiting cross-context linkage. [ADRs 8D–8E, 8Q-A, 9G-A.]
Open the relationship diagram at full size (SVG)
The diagram is informative; the cardinalities and non-inference rules above are normative candidates.