Authority
L2 specialized identity/authentication law under Constitutional Supremacy, Identity Law, Evidence Code, Data/Cognitive Privacy law, and approved IBLAS / Globe ID technical baseline.
Core rule
Identity Match ≠ Liveness ≠ Authorization.
PART I|LEGAL EFFECT
1. Identity Proof
authentication can support a legal identity claim but does not create personhood.
2. Liveness
liveness proves current live capture under a defined assurance profile; it does not itself prove authorization.
3. Authorization
transaction/action authority remains separate and purpose/scope/time limited.
PART II|ASSURANCE
4. IBLAS Profiles
Legal systems may incorporate BLA-0–BLA-6 profiles by reference; legal effect must pin version/profile.
5. High-Risk Minimum
high-value financial, identity recovery, civic/critical actions may require higher assurance.
6. Terminal Attestation
high-assurance results require trusted capture chain where the adopted profile says so.
7. Anti-Downgrade
system may not silently represent degraded authentication as full assurance.
PART III|RECOVERY & ALTERNATIVE PATHS
8. Recovery Separation
credential recovery is not ordinary transaction authorization.
9. Alternative Verification
injury, disability, atypical physiology, sensor failure or lawful non-enrollment requires an alternative lawful route.
10. Failure ≠ Guilt
authentication failure does not itself prove fraud, crime, impersonation or incapacity.
11. Degraded Mode
offline/emergency modes must disclose assurance downgrade, limit actions and create later audit.
PART IV|FORK / MERGE / SUCCESSOR
12. Fork Credential Divergence
Forks do not indefinitely share high-assurance credentials after independent legal identity.
13. Merge Reissuance
Merge requires credential review/reissuance; old credentials are not automatically combined.
14. Successor
successor status does not imply predecessor authentication token or biometric right transfers.
PART V|BIOMETRIC DATA RIGHTS
15. Template ≠ Raw Signal
systems should minimize raw biometric/neural retention when a template/verification result suffices.
16. Purpose Limitation
enrollment for identity does not automatically authorize medical inference, emotion inference, training or unrelated surveillance.
17. Revocation / Compromise
credential compromise must support suspension, reissuance, downstream propagation and immutable audit.
18. No Hidden Fallback
legacy terminal/recovery path cannot be a hidden bypass to higher assurance.
PART VI|EVIDENCE & AUDIT
19. Authentication Evidence
result should record profile/version, capture time, terminal identity, degraded state, decision, relevant failure class and audit event.
20. Dispute
a person may challenge false match, false non-match, bad terminal, wrong profile, credential history and downgrade event.