Online Account
An account within a service or virtual environment; distinct from the person's federated digital identity.
Bundle → Layer → Finding → Questions Filled
3 bundles · 4 layers · 5 findings · 10 questions
Account and holder What the account is and who controls it.
Account record
Identifier, service and status of the account.
Account identity
The service-scoped identifier and handle of the account.
- Which service holds the account, and under which identifier and handle?
- Is the account active, suspended, locked or closed?
Holder relationship
The person, organisation or agent that controls the account.
- Is the account held by a person, an organisation or a non-human agent?
- Is the holder's identity verified, and to what assurance level?
Authentication and access How the holder signs in and what the account can do.
Credentials and federation
Authenticators and linked identity providers.
Sign-in methods
The authenticators and federated logins bound to the account.
- Which authentication methods are enabled, and is multi-factor authentication on?
- Is sign-in federated through an external identity provider?
Roles and delegation
Permissions held and delegated access.
Permissions
Roles, scopes and delegated grants of the account.
- Which roles or scopes does the account hold in the service?
- Which third-party applications have been granted access, and with which scopes?
Lifecycle How the account is created, changed and ended.
Status and closure
Creation, suspension, recovery and deletion.
Closure and data
What happens to the account and its data at the end.
- Has the holder requested closure or deletion, and when?
- Which data remains after closure, and for how long?
Classifiers Filled
- Family
- World Models
- Category
- Information and virtual systems
- Entry kind
- standalone-mm
- Navigation path
- NAV.INF.VRT.ACC
- Domain
- INF.VRT.ACC
- Industry
- Cross-industry
- Tags
- onlineaccountinf.vrt.acc
What it is Filled
An online account is a record within one service or virtual environment that lets a holder sign in, keep settings and data, and act under the service's terms. It belongs to that service and is distinct from the person behind it and from a federated digital identity that may be used to sign in to many services.
Why it exists Filled
An account within a service or virtual environment; distinct from the person's federated digital identity.
Distinguishing features Filled
- It exists within one service and is governed by that service's terms.
- One person can hold many accounts, and an account can be held by an organisation or an agent.
- Distinct from a federated digital identity, which can be used across services to sign in.
- Distinct from a financial account, which holds monetary balances rather than service access.
What robots and AI may and may not do Filled
Must not
- Obtain, store or reveal account passwords, recovery codes or session tokens.
- Create accounts or sign in on someone's behalf without that person's authorisation.
- Bypass verification, rate limits or bot detection of a service.
- Link accounts across services to the same person without a lawful basis.
- Close or delete an account without the holder's instruction.
Only with a human decision
- Recovering access to an account after lost credentials.
- Suspending or closing an account for terms violations.
- Granting a third-party application access to the account.
May
- Report the status, roles and connected applications of an account to its holder.
- Flag weak authentication settings or unusual sign-in activity.
- Help the holder export their account data through the service's own tools.
Moral aspects Filled
- Accounts give access to private communications, purchases and personal data.
- Losing access to an account can cut people off from services they depend on.
- Linking accounts across services enables tracking and profiling of people.
Who is affected
- Account holders
- Service providers
- Contacts and others whose data the account holds
Owners Filled
Steward
The service provider that operates the account system answers for its records and access controls.
Master systems
- Identity and access management systems
- Customer identity stores of online services
Links to other meta-models Filled
neighbor
- world-r4-identity-register - Federated digital identity is held there; an account is local to one service.
references
- wm-per-001-person - A person may hold many accounts.
related
- wm-per-010-contact-point-party-profile - Accounts often carry contact points of their holder.
What else AI and robots need to interact with it Filled
Identity and identifiers required Filled
- An account is identified by a service-scoped identifier, often with a user name, handle or email address.
- Federated sign-in links it to an identity provider's subject identifier.
Direct properties not applicable Not applicable
Not applicable
An online account is a record in a service with no physical properties to measure.
Recognition optional Filled
- An online account has a service-scoped identifier, a holder, authenticators and a status.
- Often confused with the person, a federated digital identity or a public profile page.
Capabilities and actions required Filled
- Accounts can be created, verified, suspended, recovered, merged and closed.
- Accounts can grant scoped access to third-party applications.
Hazards and failure modes required Filled
- Account takeover through phishing, credential stuffing or weak recovery.
- Impersonation and fake accounts.
- Lock-out and data loss when recovery fails.
Standards and interfaces required Filled
- OpenID Connect and OAuth 2.0 for federated sign-in and delegated access.
- SCIM (IETF RFC 7643 and RFC 7644) for account provisioning.
- W3C WebAuthn for phishing-resistant authentication.
Context of use required Filled
- Used in every online service, platform, game and enterprise application.
- Subject to data protection law and to the service's own terms of use.
Sources Filled
- NIST SP 800-63 Digital Identity Guidelines (NIST)
- OpenID Connect Core 1.0 (OpenID Foundation)
- RFC 7643 System for Cross-domain Identity Management: Core Schema (IETF)
Open questions
- Planned model: boundary questions, research and every section remain to be written.
Machine files
Provenance
planned (registry candidate) · todo
Built from: models/runtime-index.json, ver-cy/world-models/card-supplements/wm-vrt-005-online-account.json
Planned entry, hidden from the catalogue until researched.