OWOS Federation · Root Identity Authority

One Passport. One PPID. Resolved by every OWOS app.

OVIN — the OWOS Verified Identity Network — is the root identity authority for the federation. Every Passport issued here is the canonical reference that Guardian, Calendar, OVBP, OVAK, OIVN and OCLL resolve against. No application issues identity locally, ever.

PPID

A human-readable Passport ID (OWOS-XXXX-XXXX) plus an immutable passport_id. Generated server-side here, nowhere else.

Support ID

Every identity also carries a public SUP-XXXXXX Support ID. Apps and support staff use it publicly — your PPID stays private.

Root QR registry

Exactly one active Root QR per Passport, across every class. Rotations keep history as revoked records; apps verify by fingerprint.

Federation resolution

Federation apps resolve a passport_id for status, class and active QR fingerprint. Privacy-safe by default — no PII crosses apps.

Signed module contracts

Modules authenticate with HMAC-signed requests and ES256 actor tokens against a published JWKS. Suspended modules fail closed.

Append-only audit

Every issuance, rotation, link, claim and revocation is recorded forever. No deletes — status changes only.

User-controlled app links

You decide which federation apps your Passport is linked to, approve connection requests, and revoke access at any time.

Markers, not scoring

Identity records raw system markers only. Trust scoring lives in the OWOS kernel, never inside the identity authority.

Ownership graph

Human → Business → Structure, Asset and Vehicle relations are append-only and resolvable, so authority survives ownership changes.

Passport classes

Seven canonical classes. Human is publicly live today; the rest are in internal preview while their claim and review flows finish hardening.

  • Human
    Root identity + PPID
    live
  • Business
    Operating entity authority
    internal preview
  • Charity
    Nonprofit steward identity
    internal preview
  • Structure
    Fixed property identity
    internal preview
  • Asset
    High-value durable goods
    internal preview
  • Vehicle
    Titled mobile assets
    internal preview
  • Event
    Time-bound entity identity
    internal preview
Compare every passport class →

The federation

Each OWOS module stays operationally isolated. They come back here for one thing: who this Passport is, and what it is allowed to do.

  • Guardian
    Safety + emergency response
    federated
  • Calendar (OCAL)
    Scheduling authority
    federated
  • OVBP
    Business profiles + operations
    federated
  • OVAK
    Verification & attestation kernel
    federated
  • OIVN
    Vendor intelligence network
    federated
  • OCLL
    Canonical ledger layer
    federated
  • Work
    Jobsite + work history
    reserved
  • Market
    Verified marketplace
    reserved
  • Impact
    Impact allocation
    reserved