← Back to catalogue
Published

Person

vr.wm-per-001 · wm-per-001-person

Model the natural person as a civil-identity anchor and life-course subject: a stable, referenceable identity that carries registered core attributes, scheme-qualified identifiers, evidence of identity, legal standing, life-event anchors and person-controlled personal-sphere data, so every other model can reference persons without copying them.

World Models Society, people and institutions SOC.PER.NAT

Bundle → Layer → Finding → Questions Filled

7 bundles · 14 layers · 29 findings · 103 questions

Civil identity core The registered identity itself: the anchor that other models reference, and the core attributes a registrar establishes and maintains about it.

Identity anchor and record identity

What the person entity is, how it is uniquely referenced within a domain, and how multiple records claiming the same person are reconciled.

Person identity anchor

The natural person as a persistent entity distinct from any record, identifier, document or credential about them, carrying the reference identifier every other model points to.

  1. Which identifier is the reference identifier for this person, and which authority guarantees its persistence and non-reuse? identity
  2. Does this record denote the natural person, or a registration record about the person? definition
  3. Within which domain of applicability is this identity asserted unique and resolvable? classification
  4. If no authoritative master-system identifier exists for this person, which fallback identifier is assigned, by whom, and why was the authoritative one unavailable? exception

Duplicate detection, merge and split

Several records may describe one person across systems; the model must express same-as links, merge, supersession and split without destroying history or silently unifying distinct people.

  1. Which other person records are asserted to denote the same natural person, and with what link type and direction? relationship
  2. What evidence and matching threshold justified this merge, and which role authorised it? evidence
  3. How is an incorrect merge reversed, and what happens to identifiers and credentials issued under the superseded record? exception

Exceptional identity paths

UN LIA explicitly covers persons whose birth was not registered and refugees whose proof of legal identity may be issued by the host State or an internationally mandated authority. Statelessness is a named UN LIA concern. National CRVS practice also includes foundlings, unknown parentage, incomplete dates, delayed registration and, in some jurisdictions, presumed death and later identity restoration. Those last national cases are recorded here as operating needs with incomplete global normative detail.

  1. Is proof of legal identity issued by a host State or by an internationally mandated authority for a refugee or similar status, and how does it link to this person? exception
  2. Was this identity opened for a foundling or person of unknown parentage, and which placeholder name and birth facts were assigned? exception
  3. Has legal identity been retired by presumed death or later restored, and what is the current vital status? lifecycle

Registered core attributes

The attributes a civil registrar establishes and maintains: legal names over time, birth facts, and the administratively recorded sex or legally recognised gender.

Legal name as a versioned structured fact

Legal name is a time-bounded, structured, script-bearing fact with an ordering convention, not a fixed string attribute of the person.

  1. What are the structured parts of this name and which cultural convention orders and formats them? composition
  2. Over which validity period was this the person's legal name, and which instrument changed it? temporal
  3. Is this a birth name, current legal name, former name or alias, and who may assert each? classification
  4. In which script and encoding is the name recorded, and which transliteration is authoritative for machine-readable use? interoperability

Registered birth facts

Date, precision, place and, where recorded, time of birth as registered, plus multiple-birth order, distinguished from the place and date of registration.

  1. What is the registered date of birth and at what precision is it known? temporal
  2. What is the registered place of birth, at which administrative granularity, and does it differ from the place of registration? spatial
  3. Was this birth part of a multiple birth, and what birth order was registered? measurement
  4. Which registration act established these facts, and how must a correction to them be evidenced? provenance

Sex and gender recording

Administratively recorded sex, legal gender recognition and self-identified gender are three distinct values with different code lists, owners and disclosure rules.

  1. Which code list and version encodes the administratively recorded sex, and what does each value mean in that list? classification
  2. Is a self-identified gender recorded separately from administrative sex, and who controls that value? ownership
  3. Has a legal gender recognition changed the registered value, and from which date does the change take effect? lifecycle
  4. Which of these values may be disclosed to which relying-party class, given the sensitivity of gender data? privacy
Identifiers and evidence Scheme-qualified identifiers assigned to the person, the documents and attestations that evidence identity, and the assurance produced by proofing.

Identifier schemes and correlation

How identifiers are assigned under named schemes with authorities and validity, and how their correlation properties are governed.

Scheme-qualified identifier assignment

An identifier attaches to the person under a named scheme with an assigning authority, validity period, format rule and reuse policy, without becoming the person.

  1. Under which named scheme was this identifier assigned, and by which authority? authority
  2. What is the identifier's validity period, and may it be revoked, reissued or reused for a different person? lifecycle
  3. Is this identifier a reference identifier for the person or a scoped, derived or sector-limited identifier? classification
  4. Which format, checksum or registry lookup validates this identifier value? validation

Identifier correlation and pseudonymity

Cross-domain identifiers make a person correlatable across contexts; the model must record correlatability class and any pairwise or sector-specific pseudonym derivation.

  1. Which of this person's identifiers are correlatable across domains, and what harm follows from that linkage? privacy
  2. Where a pairwise or sector-specific pseudonym is required, how is it derived, scoped and rotated? security
  3. Which identifiers may be omitted entirely from a given presentation without breaking verification? access

Identity evidence and assurance

Issued documents and electronic attestations that evidence identity, and the proofing process that produces an assurance level.

Issued identity evidence

Physical documents and electronic attestations evidence a registered identity and assert a subset of attributes; they never constitute the person and their revocation does not revoke the person.

  1. What type of evidence is this, who issued it, and over which validity period? evidence
  2. What is its current status: valid, expired, suspended, revoked, lost or stolen, and where is that status published? state
  3. Which person attributes does this evidence assert, and which of those are authoritative rather than copied from another source? provenance
  4. How is the evidence bound to the holder, cryptographically or physically? security

Identity proofing and assurance

The recorded outcome of resolving, validating and verifying a claimed identity against evidence, expressed as an assurance level with an expiry and an optional biometric reference.

  1. At which identity assurance level was this person proofed, and against which published criteria and version? quality
  2. Which resolution, validation and verification steps were performed, and with what outcome for each? process
  3. Which biometric reference, if any, was captured, in which encoding, and where is it stored? measurement
  4. When does this proofing outcome expire or require re-proofing, and what event forces early re-proofing? temporal
Legal standing The person's status in law: civil status, nationality or statelessness, legal capacity and any representation or support arrangement.

Civil status

The registered civil or marital status, its effective date, governing jurisdiction and causing act.

Registered civil status

One current registered civil status per person with an effective date and governing jurisdiction; history is carried by the acts that changed it, not by overwriting the value.

  1. What is the currently registered civil status, from which effective date, and under which jurisdiction's law? state
  2. Which registered act caused the most recent change of civil status? event
  3. How is a civil status established under foreign law recognised here, and what evidence is required? exception

Nationality and statelessness

Nationalities held, their basis and dates, and the distinct determination of statelessness or undetermined nationality.

Nationality holding

Zero, one or several nationalities held by the person, each with a coding, acquisition basis, dates and conferring authority.

  1. Which nationalities does the person hold, in which coding scheme, and from which dates? identity
  2. Which authority conferred or withdrew each nationality, and on what legal basis? authority
  3. Where several nationalities are held, which one governs a given official interaction? decision

Statelessness and undetermined nationality

Determined statelessness, undetermined nationality and simply unrecorded nationality are three different states with different consequences for document issuance.

  1. Is the person determined stateless, of undetermined nationality, or is nationality merely unrecorded? classification
  2. Which authority made the determination, when, and under which procedure? authority
  3. Which substitute documents or registration routes establish legal identity where no nationality-based document exists? exception

Legal capacity and representation

The person's legal capacity state and any arrangement by which another party supports or acts for them.

Legal capacity state

Capacity is a time-bounded, domain-scoped legal state established by a legal act, with equal recognition before the law as the default and restriction as the evidenced exception.

  1. What is the person's legal capacity state, over which effective period, and for which domains of action? state
  2. Which legal act or judgment established, restricted or restored capacity? authority
  3. Is any restriction general or limited to specified matters, and when is it reviewed? constraint

Representation and support arrangement

An arrangement by which a person or organization supports or acts for the person, distinguishing supported from substituted decision-making and recording the person's own will and preferences.

  1. Who acts for or supports the person, in which capacity, and with what scope of authority? authority
  2. Is the arrangement supported decision-making or substituted decision-making, and how is that recorded? classification
  3. When does the arrangement start, end or require renewal, and who may terminate it? lifecycle
  4. How are the person's own expressed will and preferences recorded alongside the representative's acts? evidence
Life course The person through time: anchors to registered life events, the separation of occurrence time from record time, vital status and the lifecycle of the identity record itself.

Life event anchoring and time

How registered life events attach to the person and how occurrence, registration and ingestion times are kept apart.

Vital and registered life event anchor

The person carries typed anchors to life events resolved in the vital-event model, together with the role the person played in each event.

  1. Which vital or registered life events anchor to this person, and in which model does each event resolve? relationship
  2. What role does the person play in each anchored event: subject, parent, spouse, informant or declarant? classification
  3. Which anchors are mandatory for a complete civil identity in this jurisdiction, and which are optional? requirement

Occurrence time versus record time

Every person fact carries a time of occurrence, a time of registration and a time of ingestion; conflating them corrupts history and prevents lawful correction.

  1. What are the occurrence time, the registration time and the ingestion time for this fact, and are they stored separately? temporal
  2. Which values carry an explicit UTC offset or Z, and which are deliberately dates without a time zone? validation
  3. How are late, retroactive or back-dated registrations represented without rewriting existing history? provenance
  4. Which time value governs when two sources disagree about when a fact took effect? decision

Vital status and record lifecycle

Whether the person is living, deceased or presumed dead, and which lifecycle state the identity record itself occupies.

Vital status and death registration

Vital status is an evidenced state; registered death, judicially declared death and presumed death are distinct and must not be collapsed.

  1. What is the person's current vital status and what evidence supports it? state
  2. For a registered death, what are the date, time and place of death, and how do they differ from the date and place of registration? temporal
  3. How is a presumed or judicially declared death represented differently from a registered death? exception
  4. Which downstream references, identifiers and credentials must be notified or closed when death is registered? process

Identity record lifecycle state

The identity record moves through governed states such as established, active, suspended and archived; transitions carry an authority, a reason and a timestamp.

  1. Which lifecycle state is the identity record in, and which published state vocabulary defines it? lifecycle
  2. Who may suspend, reactivate or archive an identity record, and on which grounds? authority
  3. After archiving, what remains resolvable and what is destroyed? retention
Personal sphere Data the person declares and controls: contact points, declared residence pointer, self-declared attributes and communication preferences.

Contact, presence and declarations

Person-controlled reachability, residence pointer and self-declared attributes, each explicitly flagged as unwarranted by any registrar.

Person-controlled contact point

A channel through which the person can be reached, owned and revocable by the person, with a verification state and per-purpose usage limits.

  1. What channel type and value does this contact point use, and has the value been verified? definition
  2. Who controls this contact point and for which purposes may it be used? ownership
  3. What visibility or disclosure setting applies, and can it differ per relying party? access

Declared residence pointer

A typed pointer to an address resolved in the place model, distinguishing legal domicile, registered residence and self-declared mailing address from statistical usual residence.

  1. Which address does the person declare or stand registered at, and in which model does that address resolve? spatial
  2. Is this a legal domicile, a registered residence or a self-declared mailing address? classification
  3. Over which period was it valid and who may change it? temporal

Self-declared attributes and preferences

Values supplied solely by the person, including communication and accessibility preferences, carrying no registrar warranty and always distinguishable from verified values in any projection.

  1. Which attributes are declared solely by the person and carry no authority warranty? provenance
  2. Which language and communication preferences apply, including accessible formats the person requires? quality
  3. How is a self-declared value distinguished from an authority-verified value in every projection that carries it? interoperability
  4. Which self-declared values may the person unilaterally change, hide or delete? ownership
Personal data governance Lawful basis and consent, subject-right execution, minimal disclosure, retention, erasure and disclosure audit over person data.

Lawful basis and subject rights

Why each processing purpose is permitted, how consent is scoped and withdrawn, and how subject-right requests are executed.

Lawful basis and consent grant

Each processing purpose is bound to a lawful basis; consent-based purposes carry a scoped, withdrawable grant, while statutory registration processing is not consent-dependent.

  1. What is the lawful basis for each declared processing purpose over this person's data? authority
  2. Where consent is the basis, what is its exact scope, and how are withdrawal and its propagation recorded? ownership
  3. Which processing is mandated by registration law and therefore cannot be refused by withdrawing consent? constraint

Subject right execution

How access, rectification, erasure, restriction, portability and objection requests are received, decided, executed and evidenced, including lawful refusal.

  1. Which right was exercised, when, by whom, and with what outcome? process
  2. Which data can the person rectify directly and which requires a registrar act? authority
  3. Which records are exportable in a portable form and which are excluded, and why? interoperability
  4. What lawful grounds justify refusing, restricting or deferring a request? exception

Disclosure, retention and audit

What is released to whom in what minimal form, how long data is kept, when it may be erased, and what is logged.

Minimal disclosure projection

Each relying party receives the narrowest projection satisfying its stated need, preferring a derived predicate over the underlying attribute, with special-category data excluded by default.

  1. What is the minimum attribute set that satisfies this relying party's stated need? requirement
  2. Can the need be met by a derived predicate instead of the underlying attribute? decision
  3. Which requested attributes fall into a special category requiring a stricter condition before release? privacy
  4. Which projection is released for statutory public-record requests, and what does it deliberately omit? access

Retention, erasure and disclosure audit

Retention classes and periods, the tension between permanent vital records and erasure rights, the method by which deletion is demonstrated, and what every disclosure must log.

  1. How long must each class of person data be retained, and under whose mandate? retention
  2. Which data is subject to erasure on request and which is exempt because a legal obligation requires permanent retention? exception
  3. What is logged for every disclosure, and for how long is the log itself retained? evidence
  4. How is deletion demonstrated: physical destruction, cryptographic erasure or de-identification? validation
Quality and interoperability Attribute accuracy and correction, and disciplined alignment to external vocabularies including script and transliteration handling.

Attribute quality and correction

Provenance and freshness of each attribute, the correction pathway, and the quality indicators measured over the person population.

Attribute accuracy and correction

Every core attribute carries a source and last-verified time; corrections supersede rather than overwrite, and population-level quality is measured.

  1. What is the source and last-verified time of each core attribute? provenance
  2. What triggers a correction, and which authority may make it in the register of record? process
  3. How are erroneous historical values retained for audit while no longer being presented as current? temporal
  4. Which quality indicators are measured over the person population and against what target? measurement

External alignment and encoding

Versioned mappings to external vocabularies and credential schemas, and script, encoding and transliteration handling for names.

External schema alignment

Alignments to external vocabularies are versioned, explicitly lossy where relevant, and are mappings until conformance evidence exists.

  1. Which external vocabulary or credential schema is this projection aligned to, at which version? interoperability
  2. Which parts of the alignment are lossy, and which fields have no counterpart in the target? constraint
  3. Where two aligned standards conflict on the same concept, which one governs here and why? decision
  4. Is this alignment a claim of conformance or only a mapping, and what evidence supports the claim? evidence

Script, encoding and transliteration

Names exist in native script, transliterated and machine-readable truncated forms; each form must be identified, rule-bound and reconcilable to the registered name.

  1. In which script and character encoding is each name form recorded, and which form is the registered original? interoperability
  2. Which transliteration rule set produced the machine-readable form, and is the transformation reversible? validation
  3. How are truncated machine-readable forms reconciled with the full registered name? exception

Classifiers Filled

Family
World Models
Category
Society, people and institutions
Entry kind
entity
Navigation path
NAV.SOC.PER.NAT
Domain
SOC.PER.NAT
Industry
Cross-industry
Tags
personsoc.per.nat
Also called
H1

What it is Filled

Format-neutral context structure for the natural person as a legally registered identity and data subject. Covers what an agent must know to establish, resolve, evidence, update, disclose, close and audit a person identity. Excludes the human as a biological organism, and excludes any concept that resolves in a composable sibling model (household, organization, address, vital-event record, qualification, authenticator).

In scope

  • Person identity anchor, reference identifier and domain of applicability
  • Registered core attributes: legal names over time, birth facts, administratively recorded sex and legal gender recognition
  • Scheme-qualified identifier assignments, their validity, revocation and correlation properties
  • Identity evidence: issued documents and electronic attestations, their status and holder binding
  • Identity proofing outcome and assurance level, including biometric reference pointers
  • Civil status, nationality and statelessness determination
  • Legal capacity state and representation or support arrangements
  • Anchors to vital and registered life events, with event time separated from registration and ingestion time
  • Vital status and identity-record lifecycle states
  • Person-controlled contact points, declared residence pointer and self-declared attributes
  • Lawful basis, consent grants, subject rights, minimal disclosure, retention, erasure and disclosure audit
  • Attribute accuracy, duplicate detection, record merge/split and external schema alignment

Out of scope

  • The human biological organism: anatomy, physiology, genome, clinical findings and cause of death
  • Household, family and kinship composition, including filiation ties as first-class objects
  • Population, community and demographic group membership
  • Educational, professional and occupational credentials as objects
  • Organizations acting as issuers, employers or corporate guardians
  • Address and place as spatial objects, geocoding and address validation
  • The vital-event registration record itself and its statistical processing
  • Party roles, employment, customer and account relationships
  • Authenticators, sessions, keys and login security
  • Cross-border private-international-law rules for recognising foreign status
  • Behavioural profiling, scoring and inference about persons

Why it exists Filled

Model the natural person as a civil-identity anchor and life-course subject: a stable, referenceable identity that carries registered core attributes, scheme-qualified identifiers, evidence of identity, legal standing, life-event anchors and person-controlled personal-sphere data, so every other model can reference persons without copying them.

Distinguishing features Filled

  • A person is a natural human being with legal identity, distinct from the documents and credentials that evidence it.
  • Unlike a user account or party role, one person can hold many accounts and roles in many systems.
  • It differs from the biological organism and health subject, which are separate models.
  • Registered identity is owned by a registrar while personal-sphere data belongs to the person.

What robots and AI may and may not do Filled

Must not

  • Infer identity from name, face or birth date matching alone.
  • Disclose special-category data such as health, religion or ethnicity in default projections.
  • Treat a revoked document as ending the person's identity.
  • Merge person records without evidence and a named decision maker.
  • Profile, track or score a person beyond the declared purpose.
  • Approach, touch or physically interact with a person without their awareness and a safe protocol.

Only with a human decision

  • Merging or splitting person records.
  • Recording a change in legal capacity or representation.
  • Closing an identity on death.

May

  • Resolve a person reference using scheme-qualified identifiers and recorded evidence.
  • Emit a minimal disclosure projection or a derived predicate such as over 18.
  • Record a name change or life event with its source.
  • Route a subject rights request to the responsible steward.

Moral aspects Filled

  • Every person record touches privacy, dignity and autonomy; collect the minimum and keep the person able to see and correct it.
  • Identity errors can deny people benefits, travel or healthcare, often hardest for those without strong documents.
  • Physical agents near people must protect their safety and respect personal space.
  • Children and people under representation need extra protection and must not lose capacity by default.

Who is affected

  • The person
  • Family members and representatives
  • Registrars and service providers relying on identity

Owners Filled

Steward

Name a civil registrar or register of record that owns the registered-identity bundles, and a distinct controller relationship for the personal-sphere bundle owned by the person.

Roles

Civil registrar of record
Establishes, corrects and closes the registered identity and its core attributes; Authorises merges, splits, corrections and identity-record lifecycle transitions; Publishes the register's code lists, retention schedule and public-record element list
Data subject (the person)
Owns and controls personal-sphere data, self-declared attributes and contact points; Grants, scopes and withdraws consent over their data; Exercises access, rectification, erasure, restriction, portability and objection rights; Reads their own complete record and their own access log
Identity information provider or credential issuer
Issues identifiers, documents and attestations bound to the person; Publishes and maintains evidence status (valid, suspended, revoked); Records the proofing evidence and resulting assurance level
Relying party or verifier
States purpose, lawful basis and the minimum attribute set before requesting data; Accepts derived predicates in place of raw attributes wherever they suffice; Retains only what its stated purpose requires and honours withdrawal notifications
Model steward
Maintains bundles, layers, findings, functions and their source citations; Reviews conflicts between aligned standards and records the governing choice and rationale; Approves breaking changes, deprecations and migrations of identity priority
Data protection officer or oversight authority
Reviews lawful bases, special-category conditions and the retention schedule; Audits disclosure logs, erasure decisions and refusals; Handles complaints, escalations and cross-border transfer questions

Links to other meta-models Filled

references

  • Household and family membership model (sibling; legacy alias H2) - Household membership, filiation and kinship ties are separate registered acts and separate statistical units; Person holds only typed pointers to them.
  • Population and community group model (sibling; legacy alias H3) - Group and community membership resolves against the person reference identifier and is never stored as a person attribute, particularly where it would reveal special-category data.
  • Education and qualification model (sibling; legacy alias H4) - Earned credentials anchor to the person as holder; credential content and awarding rules live in the qualification model.
  • Organization model (sibling; legacy alias O1) - Registrars, issuing authorities, credential issuers, verifiers and corporate guardians must resolve as organizations rather than being described inside Person.
  • Address and place model (sibling) - Places of birth, death and residence resolve as place or address objects; Person stores pointers plus a residence kind and validity period.
  • Vital event and civil registration act model (sibling) - The registration act, informant details, certificate issuance and statistical coding belong to the event model; Person keeps anchors, roles and resulting status changes.
  • Human biological organism and health subject model (sibling) - Explicit boundary: physiology, clinical findings, cause of death and genomic data are excluded here and must be reached only through a governed reference.

composes

  • Consent and authorization service (legacy alias S1) - Grants, scopes, withdrawal and policy decisions over person data are executed by the consent service; Person declares what is subject-owned and which purposes exist.
  • Audit and evidence service (legacy alias S4) - Disclosure logs, lifecycle transition logs and correction records are written to the audit service so the person and oversight authorities can read them.
  • OASIS CIQ v3.0 xNL and xAL value shapes - Reuse structured, culture-aware name and address value shapes instead of re-inventing name part roles and ordering conventions.

aligned

  • ISO/IEC 24760-1:2025 identity management framework - Adopt the entity/identity/identifier/reference-identifier distinction and identity-register and relying-party roles as the model's conceptual vocabulary; the exact lifecycle state list must be bound to a published Dimension vocabulary.
  • Core Person Vocabulary 2.00 (SEMIC) - Map name components, birth and death facts, citizenship, domicile and the Identifier class with scheme, issuing authority and issue date.
  • EUDI Wallet PID Rulebook (ARF Annex 3.01) - Map the person identification data attribute set for wallet-based presentation, including predicate attributes such as age_over_18 and the issuer-defined personal administrative number policy.
  • W3C Verifiable Credentials Data Model v2.0 - Express identity evidence as credentials with issuer, subject, validity window, status and proof, and use presentations for selective disclosure.
  • W3C Decentralized Identifiers v1.0 - Provide the governed global identifier option at identity-priority level two, with documented correlation risk and controller-versus-subject separation.
  • NIST SP 800-63A-4 identity proofing and enrollment - Adopt resolution, validation and verification as recorded proofing steps producing an assurance level, while keeping authenticator management outside this model.
  • HL7 FHIR R5 Patient - Map to care-context demographics and reconcile the one-anchor-per-person rule with FHIR's multiple Patient records via link semantics rather than merge.
  • schema.org Person - Provide a lossy public publication projection only; no validity periods, authority or assurance semantics may be inferred from it.
  • ISO/IEC 5218:2022 codes for the representation of human sexes - Bind the administrative sex code list, noting the standard's explicit exclusion of gender identity, which forces separate modelling of self-identified gender.
  • ICAO Doc 9303 Part 3 (Eighth Edition, 2021) - Bind machine-readable-zone name transliteration, truncation behaviour and biometric image encoding used by travel-document evidence.
  • Regulation (EU) 2016/679 (GDPR) - Regional legal alignment for lawful basis, special categories, accuracy, storage limitation and subject rights; other jurisdictions require their own binding.

neighbor

  • Human biological organism / health subject model - This model treats the person as a civil identity, not an organism. HL7 FHIR Patient covers care-context demographics and explicitly permits several Patient records for one human; the anchor here is one per natural person and reconciles to Patient records by link, not by absorbing them.
  • Household and family model (legacy alias H2) - Kinship, filiation and household membership are separate registered acts and separate statistical units in UN civil-registration guidance. Person holds only typed pointers to them, never the tie itself.
  • Vital-event / civil-registration act model - The registration act, its informant, its statistical coding and its certificate are the event model's content. Person holds the anchor, the person's role in the event and the resulting status change only.
  • Address and place model - Residence is a pointer with a kind and a validity period. Address value shapes come from OASIS xAL and place resolution from the place model; usual residence as a statistical construct belongs to the census/statistics model.
  • Organization model (legacy alias O1) - Registrars, issuing authorities, credential issuers and corporate guardians are organizations. Person references them; it does not define them.
  • Credential and authenticator security model - NIST separates identity proofing and enrollment from authenticator management. This model carries the proofing outcome and assurance level; authenticator binding, lifecycle and session security are out of scope.
  • Consent and authorization service (legacy alias S1) and audit service (S4) - Person declares which data is subject-owned and what must be logged; the grant store, policy decision point and audit trail are service-layer components composed in, not duplicated here.
  • Publication vocabularies (schema.org Person) - schema.org Person is an open publication vocabulary with no validity periods, no issuing authority and no assurance semantics. It is a projection target only and must never be treated as an identity-assurance signal.

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative master-system identifier: the civil register or population register entry identifier issued by the registrar of record for the jurisdiction.
  • Governed global identifier or IRI: a resolvable identifier under a named, governed scheme such as a DID or registry IRI, used where no civil register identifier exists or where law forbids its use.
  • UUID or ULID assigned by the adopting Dimension, used only as a local surrogate and never presented externally as a civil identifier.
  • A date, a name, a name plus date-of-birth combination, a biometric template or any other demographic attribute set is not an identifier and must never be used as a key.

Direct properties required Filled

  • Position and distance of the person from the agent in metres, measured continuously while the agent moves or acts nearby.
  • Approach speed of the agent relative to the person in metres per second, measured at the closest point.
  • Contact force and pressure in newtons and pascals when physical contact is part of the task, measured at the contact point.
  • Body height in metres only where a task requires it and the person agrees, measured standing.

Recognition required Filled

  • A person is recognised through scheme-qualified identifiers, names, birth date and evidence documents, never by one attribute alone.
  • Confused with an account, a party role, a namesake, a twin and a representative acting for the person.
  • Physical presence of a person must be detected for safety even when the person is not identified.

Capabilities and actions required Filled

  • Resolve person reference: Resolve a set of candidate identifiers and attributes to a single person reference identifier within a declared domain of applicability, or report non-resolution.
  • Register person identity: Establish a new person anchor from a civil registration act, or from a recorded exception route where no registration act exists.
  • Record name change: Add a new time-bounded legal name assertion and close the validity of the prior one without deleting it.
  • Assign scheme-qualified identifier: Record an identifier issued to the person under a named scheme with authority, validity, reuse policy and correlatability class.
  • Record identity evidence: Register an issued document or electronic attestation as evidence about the person, with issuer, validity, asserted attributes, holder binding and status source.
  • Assess identity assurance: Run and record resolution, validation and verification against collected evidence and emit an assurance level with an expiry.
  • Anchor life event: Attach a typed anchor to a registered life event resolved in the vital-event model, recording the person's role and the three time values.
  • Record legal standing change: Record a change of civil status, nationality, statelessness determination, legal capacity or representation arrangement with its authority and effective period.
  • Close identity on death: Record registered, judicially declared or presumed death, transition the identity record lifecycle state and drive downstream closure.
  • Merge or split person records: Apply a same-as, merge or split decision across person records, preserving both records' histories and keeping superseded identifiers resolvable.
  • Emit minimal disclosure projection: Produce the narrowest attribute projection or derived predicate that satisfies a relying party's stated need, and log the disclosure.
  • Execute subject right request: Intake, verify, decide and execute an access, rectification, erasure, restriction, portability or objection request, including lawful refusal.
  • Apply retention or erasure decision: Evaluate a retention class against its schedule and legal obligations, then retain, suppress, de-identify or destroy, and evidence the outcome.
  • Revoke identity document: Invalidate a document before expiry and record revocation time, authority and reason.

Hazards and failure modes required Filled

  • Physical injury when an agent moves near or in contact with a person.
  • Wrong merge mixes two people's records, with health, legal or financial consequences.
  • Identity theft or exposure through over-disclosure.
  • Surveillance and discrimination through linking records across sources.

Standards and interfaces required Filled

  • ISO/IEC 18013-5 mobile driving licence.
  • W3C Verifiable Credentials Data Model 2.0.
  • eIDAS Regulation (EU) No 910/2014 as amended by Regulation (EU) 2024/1183.
  • ISO/IEC 29100 privacy framework.
  • ISO 10218 and ISO/TS 15066 for safety of robots working near people.

Context of use required Filled

  • Data-subject rights, lawful bases and special-category rules are stated in EU terms (GDPR); other jurisdictions require their own binding and may lack an erasure or portability right entirely.
  • The person identification data attribute set is EU-specific (EUDI ARF); other regions use different mandatory attribute sets, and the personal administrative number's uniqueness policy is issuer-defined rather than harmonised.
  • CRPD Article 12's shift from substituted to supported decision-making is ratified unevenly and interpreted differently; many jurisdictions still operate plenary guardianship, so the model records arrangement type rather than assuming supported decision-making.
  • Civil status vocabularies, name-part conventions, name-ordering rules and national personal identifier schemes are jurisdiction-specific and must be bound in the owner package.
  • Alpha-2 country coding for nationality does not represent statelessness, undetermined nationality or contested territories well; the model therefore carries a separate nationality determination status.
  • Legal gender recognition regimes vary from unavailable to self-declaration-based, which changes both the permitted values and who may change them.
  • NIST assurance levels are a US federal framework; European and other schemes use different level definitions that are not one-to-one mappable.
  • UN CRVSID is treated as the global operating frame: civil registration as identity factory, identity management as credentialing, vital statistics as reuse. Common-law splits between vital records and identity cards, and Nordic population registers, must be mapped into that frame rather than assumed identical.
  • Age of majority is jurisdiction-specific; GDPR Article 8 child-consent ages vary by Member State.
  • Latin MRZ transliteration is mandatory for ICAO documents even when the legal name is in another script.
  • EU eIDAS PID and CPV are authoritative inside the Union and alignments elsewhere, not world law.
  • Refugee identity may be issued by UNHCR or another mandated authority only where the host State so recognises.

Sources Filled

  1. Principles and Recommendations for a Vital Statistics System, Revision 3 (Series M No. 19/Rev.3) - United Nations Department of Economic and Social Affairs, Statistics Division
  2. United Nations Strategy for Legal Identity for All (UN Legal Identity Agenda) - United Nations Legal Identity Expert Group / UN Statistics Division
  3. ISO/IEC 24760-1:2025 Information security, cybersecurity and privacy protection - A framework for identity management - Part 1: Core concepts and terminology - ISO/IEC JTC 1/SC 27
  4. Core Person Vocabulary (CPV) 2.00 - European Commission, SEMIC / Interoperable Europe (formerly ISA2)
  5. EUDI Wallet Architecture and Reference Framework, Annex 3.01 PID Rulebook - European Commission, European Digital Identity Wallet consortium
  6. Verifiable Credentials Data Model v2.0 - World Wide Web Consortium (W3C)
  7. Decentralized Identifiers (DIDs) v1.0 - World Wide Web Consortium (W3C)
  8. NIST Special Publication 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment - National Institute of Standards and Technology (NIST), U.S. Department of Commerce
  9. FHIR R5 Patient Resource - Health Level Seven International (HL7)
  10. schema.org Person - schema.org (W3C Schema.org Community Group)
  11. Regulation (EU) 2016/679 (General Data Protection Regulation) - European Parliament and Council of the European Union
  12. Art. 9 GDPR - Processing of special categories of personal data - gdpr-info.eu (unofficial reproduction of Regulation (EU) 2016/679)
  13. ISO/IEC 5218:2022 Information technology - Codes for the representation of human sexes - ISO/IEC JTC 1/SC 32
  14. Doc 9303, Machine Readable Travel Documents, Part 3: Specifications Common to all MRTDs - International Civil Aviation Organization (ICAO)
  15. Convention on the Rights of Persons with Disabilities, Article 12 (Equal recognition before the law) - United Nations / OHCHR
  16. Customer Information Quality (CIQ) Specifications Version 3.0 - Name (xNL), Address (xAL) and Party (xPIL) - OASIS Customer Information Quality Technical Committee
  17. Guidelines on the Legislative Framework for Civil Registration, Vital Statistics and Identity Management Systems - United Nations Department of Economic and Social Affairs, Statistics Division
  18. Core Person Vocabulary (CPV) 2.1.2 - European Commission SEMIC / Interoperable Europe
  19. United Nations Legal Identity Agenda — operational definition of legal identity - United Nations Department of Economic and Social Affairs, Statistics Division
  20. Handbook on Civil Registration, Vital Statistics and Identity Management Systems: Communication for Development - United Nations Statistics Division
  21. ISO/IEC 24760-1:2019 IT Security and Privacy — A framework for identity management — Part 1: Terminology and concepts - ISO/IEC JTC 1/SC 27
  22. ICAO Doc 9303 Machine Readable Travel Documents, 8th edition - International Civil Aviation Organization
  23. OASIS Customer Information Quality Specifications Version 3.0 — Name (xNL), Address (xAL), Name and Address (xNAL) and Party (xPIL) - OASIS Customer Information Quality Technical Committee
  24. Regulation (EU) No 910/2014 (eIDAS) as amended, and person identification data for European Digital Identity Wallets - European Parliament and Council of the European Union; European Commission implementing acts on PID
  25. UN Convention on the Rights of Persons with Disabilities, Article 12 — Equal recognition before the law - United Nations Enable / UN DESA
  26. Review — ISO/IEC 24760-1:2019 - IDPro Body of Knowledge

Open questions

  • Dedicated minority finding: age of majority and its jurisdictional variation, emancipation, and GDPR Article 8 child-consent thresholds, plus child-specific identity protections (preservation of identity, adoption record sealing and later access) that the base flagged as a likely addition.
  • Citizenship as a legal tie to a jurisdiction versus nationality as encoded on travel documents: verify CPV and ICAO wording and decide whether the base nationality-holding finding is retitled or split, rather than adding a third overlapping node.
  • Residency and habitual residence as a jurisdiction tie distinct from the address-typed domicile pointer, including which one governs applicable law; extend declared-residence-pointer rather than duplicating the contact layer.
  • Foundlings, unknown parentage, confidential birth (including accouchement sous X), intersex civil markers, and identity restoration after a presumed or judicially declared death: no primary UN paragraph was located by either provider.
  • Cross-border recognition of foreign civil status, foreign gender recognition and foreign capacity decisions, including the Hague Convention on the international protection of adults and apostille legalisation of civil documents, which neither provider fetched.
  • Digital-identity assurance beyond the sources used: World Bank ID4D practice, and reconciliation of NIST SP 800-63A-4 assurance levels with eIDAS levels of assurance, which are not one-to-one mappable.
  • Biometric modality profiles (ISO/IEC 19794 and 39794) and the template-protection, retention and matching-threshold rules that follow; both providers reference biometrics only as pointers and neither found an authoritative matching threshold for cross-script name matching.
  • Deceased-person data handling after death and posthumous personality or digital remains, where most data-protection regimes stop applying while permanent registry obligations continue.
  • ISO/IEC 24760-1:2025 and ICAO Doc 9303 are paywalled; their catalogue and store pages were retrieved but the normative clause text was not. Definitions and lifecycle states from these standards are therefore treated as alignment targets to be bound, not reproduced as canonical.
  • EUR-Lex retrieval of Regulation (EU) 2016/679 failed repeatedly during this research; the Article 9(1) special-category wording was verified against an unofficial reproduction (SRC-012). The OJ text remains governing and should be re-verified before implementation.
  • OHCHR retrieval of the CRPD returned HTTP 403; Article 12(2) wording was verified from quoting sources rather than the treaty page itself.
  • The UN Principles and Recommendations Rev. 3 PDF could not be text-extracted by the tooling; its publication metadata and the vital-event list were confirmed via the UNSD Standards and Methods catalogue page rather than the document body, so paragraph-level citations are not given.
  • No dedicated source was consulted for indigenous, customary or non-state identity registration practices, nor for refugee and forced-displacement registration systems (for example UNHCR registration), which would likely add a finding on alternative registration routes.
  • Biometric modality specifics (ISO/IEC 19794 and 39794 profiles), and the retention and template-protection rules that follow from them, are referenced only as pointers and not modelled.
  • Child-specific protections beyond birth registration (right to preservation of identity, adoption record sealing and later access) are not given a dedicated finding; they were identified as a likely addition.
  • Deceased-person data handling after death, where most data-protection regimes stop applying but registry obligations continue, is only partially covered by the retention finding.
  • Machine-readable name matching across scripts is modelled structurally, but no normative matching algorithm or threshold is recommended, because none was found with sufficient authority.
  • No extracted primary UN paragraph was located in this pass for foundlings, confidential birth (including accouchement sous X), intersex markers, or identity restoration after presumed death; those are recorded as likely operating cases, not as canonical UN rules.
  • ISO/IEC 24760-1 normative text is paywalled; terms used here are those confirmed by the ISO abstract/OBP statement and the IDPro review.
  • Religious personal-status systems and indigenous naming authorities beyond CIQ extensibility are not specified.
  • Population-register (Nordic-style) versus event-register architectures are acknowledged by UN LIA interoperability language but not modelled as alternative masters.
  • Posthumous personality, digital remains, nasciturus/unborn legal subjectivity, and biometric matching thresholds lack primary support in the sources used.
  • World Bank ID4D, NIST SP 800-63 and W3C DID/VC were not fetched within the source budget; they are likely omissions for digital-identity assurance and self-sovereign identifiers.
  • Hague conventions on protection of adults and apostille legalisation of civil documents were not fetched.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-per-001-person/spec.yaml, ver-cy/world-models/card-supplements/wm-per-001-person.json