W3C

VCWG Recognized Entities

21 July 2026

Attendees

Present
dmitri_zagidulin, elaine_wooton, kayode_ezike, kevin_dean, manu_sporny, parth_bhatt, phil_archer, Steve Capell, ted_thibodeau_jr, todd_snyder
Regrets
-
Chair
-
Scribe
transcriber

Meeting minutes

Meeting Kickoff And Agenda

Manu_Sporny: All right, let's go ahead and get started. welcome everyone to the recognized entities call for this week. we have a number of things on the agenda. largely a review of the GS1 use case. so for a while now we have on our list of things to do to demonstrate how recognized entities can apply to the GS1 use case. PR has been put in. There have been multiple reviews of that. Thank you very much for everyone that reviewed. We'll be going into that in detail today on also just before this call got one for the UN grid use case.

Manu_Sporny: Steve it is not quite in the shape I want it to be but it's a demonstration of progress towards documenting how this hopefully addresses the UN grid digital identity anchor use case as well. and then the other kind of question in front of the group today is whether or not we want to kick off horizontal review as soon as possible. And so we'll spend a little bit of time talking about that. And in fact, maybe we start the call out with that because I think we could definitely spend the rest of the time deeply engaged in the GS1 and UN grid use cases.

Manu_Sporny: the question that you're asking in chat, Steve, when does the editor's draft of the specification get published to TR space? It is supposed to happen every time we merge something down to the main branch. However, I am looking at the build and deployment logs and it looks like something's failing somewhere. That is typically because the publication process will stop the publication to if there is a syntax error or any error of any kind that would, make the spec not render nicely.

Manu_Sporny: So there's an extra level of cleanliness that space exa expects from the specification. So it'll stop a publication if it finds a syntax error and it looks like we might have accidentally introduced one a while ago. It looks like two weeks ago we introduced one and…

Manu_Sporny: we haven't fixed it. So we'll need to look into that. okay.

Steve Capell: Okay. Yes,…

Manu_Sporny: Did that answer your question, Steve? Okay.

Steve Capell: it is. Thank you.

Specification Publication Status

<Steve Capell> quick quesiton for the group - when does Recognized Entities v1.0 get deployed to Recognized Entities v1.0 ?

Manu_Sporny: I'll take a look at that and see what's going wrong. that is the proposed agenda for today. Any other updates or changes of the changes to the agenda?

Manu_Sporny: Anything else folks would like to discuss today? you're Thank you.

Steve Capell: Trying to find the hand up button.

Steve Capell: I was speaking anyway.

Manu_Sporny: Go ahead.

Recognized Entity Scope Discussion

Steve Capell: I was just doing a mapping to the digital identity anchor and I think it meets pretty much all the needs. There is one thing that is a little different and I just wanted to get the group's feedback. So when a recognizing entity an issuer the Australian tax office says I recognize this party using a recognized entity credential. there is sometimes a scope or a type.

Steve Capell: So for example in an Australian business register some businesses are forprofit legal entities some are not for profofit some are registered for GST and some are not there sort of subtype information And in the DIA we put it as a kind of the scope of recognition which is slightly different in concept to recognize which is in the current recognized entity. It says we recognize this party and we recognize them to perform these actions. recognize it's more recognized as not for profofit whatever.

Steve Capell: Is that something we would consider just an extension that doesn't need to be specified in the spec? So if we want to put it in there, we just put it in there, but it's not in the spec. is the concept of as opposed to recognized to something worth considering? Yep.

Manu_Sporny: I think the answer is the first thing you mentioned which is it's an extension and you can add it and that's the whole beauty of verifiable credentials it's an open world model and so you can extend it as you see fit for the use cases you see fit. So, this group doesn't necessarily need to be concerned about that. we may want to talk a little bit about I mean, we'll want to kind of discuss that a bit more to make sure that we're absolutely positive about that.

Steve Capell: Mhm. That's right.

Manu_Sporny: But I think the short answer is it's an extension. You can put it in there if you want to. This group doesn't really need to say anything, about it. We don't need to give other people position permission to extend u by design, and let's pick that up in the section where we talk about the UN grid use case. I think we can kind of explore that a bit bit all right. So let's go ahead and jump into the agenda. I didn't hear any additions.

Horizontal Review Process

Manu_Sporny: I think the first kind of question is should we kick off a horizontal review? So I'll kind of cover what horizontal review is about just to remind everyone and introduce those that are new to the concept. So C as a part of its standardization process requires something called horizontal review. that means that there are groups other than us that take a look at our specification and determine whether or not it meets their needs from for example a privacy standpoint or a security standpoint or internationalization standpoint accessibility standpoint or from a general web a technical architecture group standpoint.

Manu_Sporny: So there are five groups there at W3C that do horizontal reviews. And kicking off horizontal review just means hey we would like to be on your review queue. Please take a look at our specification. When you kick that process off. It can take up to six months for them to get around to it. Ideally, it's within three months. Some groups time out and they never are able. They're just underst staffed and they can't get around to reviewing your particular specification. other groups, for example, accessibility might look at our specification and go like, "Yeah, there's not really anything you're working on from an accessibility perspective or internationalization perspective, right?"

Manu_Sporny: So some reviews are quick, other reviews take a bit longer. we have prepared all of the documentation necessary the threat model our relationship to other technologies section in our specification like the accessibility self-review or the privacy and security self-re. We've done all of that stuff and we have all the documentation ready. The very next step is us officially requesting. So that's what this current discussion is about. Do we want to officially request a review of our specification? there multiple times at which You can request it at when you do your first public working draft. We didn't do that because we felt we were going to be here pretty quickly, which we did get here, fairly quickly.

Manu_Sporny: you are required to ask for it before So you cannot go into candidate recommendation without at least asking for it and I believe it's at least 3 months passing before not having a review and hopefully they get back to us before the review. so we are at the stage where we're pretty feature complete, I think. there can still be quite a little bit of adjustment here and there, but we think, the spec is pretty cohesive right now. so now is the right time to kind of ask for it and say yeah, we think we're more or less done. and then, we wait for that review. It doesn't mean we stop work.

Manu_Sporny: doesn't mean we can't add new features or massively change the specification. we can still continue to do those things over the next couple of weeks. So, let me pause there, see if there are any questions on what a horizontal review is or…

Manu_Sporny: why we're asking for it now or any of that stuff.

Todd_Snyder: I think you hit on it,…

Todd_Snyder: but what groups would do the review? Is there anything specific about this working group?

Todd_Snyder: We need certain sign off, I guess, security, right, from the threat model.

Manu_Sporny: It's standard.

Horizontal Reviews for VC Recognized Entities v1.0 · Issue #95 · w3c/vc-recognized-entities · GitHub

Manu_Sporny: There are multiple groups that you have to ask. It's always five groups. You don't get to pick and choose. they are listed here. Let me put in issue 95 and I'll share my screen just so we can see it. these are the five horizontal review groups.

Manu_Sporny: It is the W3C tag which is the technical architecture group. They look at it from kind of a highlevel web architecture. Does it fit into the architecture of the web perspective? accessibility that's a 111y is just the word accessibility spelled out. accessibility looks for like do you do anything with fonts? Do you do anything with rendering? if the person looking at your thing can't see? What if they can't hear? What if they have motor impairments? that's what accessibility does. and then internationalization's next is the technology you're working on meant to be used by people that speak a different language than you?

Manu_Sporny: how do you convey what you're doing in English and French and Ganji and Sanskrit and those kinds of things is the letter ordering to left fonts what are you doing for that that's what they care about security is the threat model do you have something that's defensible have you thought about all the types of attacks on your system. What does that look like? And then privacy is okay, your system's doing something and it's doing something on behalf of a organization or an entity or person. have you considered what the privacy implications of the technology? Are you protecting the person's privacy? Are you creating some giant honeypot of information that's going to be stolen and that sort of thing? So, these are the standard five groups.

Manu_Sporny: and those are the ones that we are required to request review from. There are also liaison groups listed in our charter where we're supposed to ask them to kind of take a look and review as well. we kind of take care of that because every week we autopublish what we're working on the issues and pull requests. we publish our minutes online to people that are on those mailing lists that are hopefully paying attention to the weekly report outs we're doing. did that answer your question Todd on what are the groups and you might be muted if you said anything.

Todd_Snyder: Yeah. No, thank you. I just wanted to make sure that was clear on what groups.

Manu_Sporny: Yep.

Manu_Sporny: It's these five groups specifically.

Todd_Snyder: Yeah. No more questions. It makes sense where we are to kind of start the process.

Manu_Sporny: Any other questions, concerns about kicking this off? All right. Then I'll ask concretely. Does anyone have any objections? to requesting horizontal review. if nobody has any objections, I will open issues on each one of these issue trackers. That is how you request review. I will fill out all the requisite paperwork and that will start the process. and then when we hear back from them. it usually takes multiple months for them to get back to us.

GS1 Federated Identifier Example

Manu_Sporny: All right, then. hearing no objections, I will kick that process off. Thank you all right, that is that item. Next up, let's jump into the federated identifier example. And bring let me topic this is pull request 103 and I've rendered it on my machine. okay. So, how about this?

Manu_Sporny: Phil, Todd, Kevin, do one of you want to kind of introduce what this use case is about and…

Manu_Sporny: then I can walk through each section here.

Add complete GS1 Federated Identifier example. by msporny · Pull Request #103 · w3c/vc-recognized-entities · GitHub

Phil_Archer: I'm out walking the dog talking on my phone…

Phil_Archer: but I will do my best. the JSON model is pretty straightforward in that there is a route authority called GS1 global office which issues prefixes which are three digits long to its member organization It's member organizations then issue numbers based on that number ranges based on that and those are issued to an individual company and that individual company then extends that to create the full identifier the global trade item number the global location number or whatever it may be and so there's a chain there and that's what the diagram in front of you I think very accurately depicts I think the issue

Phil_Archer: that I'd like to make sure everyone we do have consensus on so I'm wearing my GS1 hat here not my chair hat wearing my GS1 hat it's really really helpful I think to us that there is an example of how to do this whilst it would be great if it's the perfect example and has every detail of GS1 that obviously be ideal deal. But I don't think we have to push for that. I think if the W3C spec shows how it can be done, there is a line then where GS1 has to take over. And in its documentation which

Phil_Archer: which we will update accordingly publishes the details so where's the boundary between we need this in the example and how much do we leave to GS1 to publish themselves but I'm very happy to see this and obviously I'm very keen to hear what other people think I guess Todd and Kevin first on the list but other people what you think about that where is the line between what this spec has to do and what GS1 publishes we will publish what we need published. We will publish our JSON schemas. something we haven't done yet that we will do is publish the digests of those. I might need some help from Todd to do that, but we can do that easily enough. So assume that's going to get done and we'll try and do it quite quickly as well. But where's that line between what goes in this spec and what GS1 has to do? That's my question.

Manu_Sporny: Thank you, Phil. go ahead, Kevin.

Kevin_Dean: Yeah, like Phil, I'm working from home and also driving in a rural area in a rainstorm. So, I may lose a connection, but I think the dividing line between the two is that for recognized entities, we have to establish a standardized way to link credentials together. I have the right to issue this credential because of this other credential that has been issued to me. And that W3C should go. I think that's as far as logically they can go.

Kevin_Dean: when you get into the specific problem domain of GS1 or any other linkage of credentials, there are additional constraints that will be placed upon my right to issue credent by the issuer of the credential on which I am basing my privilege. So in the GS1 world, I can issue an identifier for this product because I have been issued because I have a GS1 company prefix license credential from a GS1 member organization. that's a type linkage. I can issue this type of credential because I have been issued that type of credential.

Kevin_Dean: But within that type of credential, there's a business level constraint that says I can issue within this range of identifiers. I can't issue just any product identifier. It has to be within a range that is constrained as described in the credential on which basic my issue is. So I think that's where the dividing line is.

Manu_Sporny: All good points all around. so Phil, completely agree with, were thing. and that's what we're going to be discussing during this hour is, where's dividing line? how specific do we want to be? plus one to what you also said Kevin, there's only so much we can do in our spec before we have to hand it off to a different ecosystem to make those fine grained decisions and some of the more fine grained issuance and usage things that Kevin was mentioning. So yes, plus one all of that.

Manu_Sporny: With that in mind, I'd say let's go through the example and take a look at what we have here. There were a number of things that Todd pointed out on his review that you pointed out as well Phil that I want to make sure that we get this I need to understand what to update in the example so that we can get this emerged into the spec. I don't have a strong opinion or feeling about any of this stuff, I want to make sure that and just speaking as an editor, I just want to make sure that GS1 feels like what they need is in the spec that they can then point to and extend in the way they feel is appropriate. So let we start off in an appendex.

Manu_Sporny: This is an informative appendix that is about eem 1 is one of the ecosystem examples. UN grid is another one. we might add another one in the future, but this is kind of where we're explaining how this technology can be applied concretely in different ecosystems. Avon asked for this diagram. I created a rough one. Avon made it better. This is Avon's diagram and as Phil was mentioning as he talked through it. I was able to kind of point to places at the diagram and I think it makes sense. So that's good. We can update it at any point, change it colors, shapes, text, however we want to. But that's kind of there.

Manu_Sporny: And then we kind of talk through it using concrete examples as we go through each section. So we start off at GS1 global office recognizing a GS1 member organization. We talk about that and then about we show the example specifically. But Kevin, you've got your hand up. Please go ahead.

Kevin_Dean: No, it didn't go down. And I'll take it down.

Manu_Sporny: No problem. so we start at the top here, right? So we start at Global office issuing a 950 prefix to GS1 Utopia u member

Manu_Sporny: organization. there I mean and the example is pretty straightforward, right? it does pull in there a couple of details here where I'm like I wasn't quite sure what to do here. So we pull in the license context. I don't know if that's the right thing to do or not. let me point out the things I'm unsure about. License context. I don't know if we should pull it in or not. Clearly the examples context shouldn't be in there. so we might need to clean up some stuff here. this is the issuer of it is a recognized issuer GS1 global office. This is the root of trust identifier that people would put into their software. they talk about GS1 Utopia which is a member organization as a recognized entity.

Manu_Sporny: They provide their legal name, a description stating that they're the lency of the GS1 950 prefix license value in here. it probably shouldn't go in here, Todd. This was one of your questions and…

Manu_Sporny: I was like, Should it just be a part of the JSON schema? Should you mix in other data into this thing? Mhm. Mhm.

Todd_Snyder: Yeah, this gets into to my one the questions I have I guess just to clarify something so it's clear to everyone.

Todd_Snyder: I think it is but just to be 100% sure a entity in this case a GS1 memorization will have multiples of these issued right so the US I think we have a hund of them or something there's quite a few and then other ones may only have one so you do need something that distinguishes the value in so this case is we're saying that the utopia has access to 950 so the US doesn't have access for example so US can't start any company prefixes or other identifiers we generate because this one is owned by Utopia. So I think you do need the value here. My question was looking at our current way we do things it almost felt like this was a replacement and…

Todd_Snyder: not a pair and that's the part that was not clear to me from the initial look of it…

Manu_Sporny: Mhm.

Todd_Snyder: because like you said you're referencing our license context. that's the same thing. So I guess one thought is the type always a recognized identity or…

Manu_Sporny: Mhm.

Todd_Snyder: is this a GS1 recognized identity credential or do we add a third type and kind of combine them in again our use case we kind of combine them together because it feels redundant in some ways too. So, from I believe what we're trying to solve, and Phil can correct me if I'm wrong, we do need some way to put in that information because that's really when we verify our credential chain,…

Todd_Snyder: we need to know the values and we need to know that the things that come off of this guy also are based on the 950. Go ahead, Phil.

Phil_Archer: Yeah, I think is that we do treat these as recognized identity credentials.

Phil_Archer: And I'm flipping between different worlds here. I think that what we call a GS1 license you can have 950. I think that is a recognized entity credential and what manage example shows is the use of a reg x to include that 950 element of it. So that's Jason schema.

Phil_Archer: could be separate. but we do either way. I don't think it matters really, but it's really needed to do in this is a generic recognized entity credential that is defined by W3C model and it's only recognized to issue credential other licenses beginning 950. that's a very GS1 specific thing presented in this document as a hey, if you're doing the same thing,…

Phil_Archer: here's where you put your prefix or whatever because there are others that we want to cover. but I think Todd, you and I need to work with Paul as soon as we can to help Manu to actually provide our side of this because,…

Todd_Snyder: Mhm. Yep.

Todd_Snyder: So, I think this is open question, Mono. I think for now it's good to Yeah.

Phil_Archer: the poor guy is trying to do his best to help us and we haven't got our level.

Todd_Snyder: I think for now I wouldn't say it stays in but it may be open later to be removed because I see again on they list your line numbers here in the output validation again you list the 95 value so maybe that would have will solve that too but I'm also open to maybe we don't include it now we could always add it later right so I'm from a technical point of view I'm fine with either one as long as there's some way to distinguish that this is this specific instance so I would imagine

Todd_Snyder: and there's recognize entity credentials for every one of those instances. or maybe there's because they get issued separately. So this gets more complicated as we move down our chain as we issue to two actual member organizations or sorry member companies because they buy stuff at different periods of time, So they could buy three of them today and tomorrow four other things. and each one of them would have their own unique identifier associated with it.

Manu_Sporny: Phil, you were breaking up on us a bit there, but I think I got everything.

Phil_Archer: I'm sorry.

Manu_Sporny: Plus one to that, I think there are three paths for it, and it's totally fine. we can rework this example multiple times over the next couple of months this is not like we need to absolutely figure this out this week. There are three approaches that I can see. one of them is to rely entirely on the JSON schema. And that is where you do your restriction on what this GS1 utopia member organization should be able to issue. So what there's one I don't want to say extreme but one end of the spectrum where we're just saying no it's the JSON schema that is the thing that really ties this stuff down.

Manu_Sporny: The other approach is to bring the logic out of the JSON schema and put it in the credential itself and put license value and some business rules here where you're kind of like decorating the recognized entity credential with GS1 specific stuff. So remember that for a credential subject type it can be multi-yped. So it can be both a recognized entity and a GS1 recognized entity which you would expect to have a license value or whatever other properties you want to put on it, right?

Manu_Sporny: And so all that to say that in the same way that we were talking about for Steve's UN Grid use case, those are extensions that are with entirely within GS1's domain and you can add them at any point that you'd like to. so I think one way is put absolutely everything in the JSON schema. The other way is mix the data into the credential and then the third way is issue an entirely separate credential which is basically what you're doing right now and then we figure out some way to link them together. I't I think the last option is probably the not so good option.

Manu_Sporny: The other two ones, mixing the data in or putting the logic entirely in the JSON schema, feel like workable paths forward. And I think it would be really good to figure this out with the UN grid and the GS1 use case to make sure we're all comfortable with it because I think this design pattern is going to pretty much be the same for most other ecosystems that have this type of setup that you guys do.

Manu_Sporny: Go ahead, Todd.

Todd_Snyder: Yeah, a couple things.

Todd_Snyder: I like the idea of trying to use the JSON schema because that's kind of part of the verify credential specification. I just don't know if we could solve it all in one shot. and the other thing that you highlight the ID here is this is not a company prefix license credential because that will confuse people later.

Todd_Snyder: So if you can change that just to prefix license.

Manu_Sporny: Got you.

Todd_Snyder: Is it a company prefix? then yes I will try.

<Steve Capell> I suspect that the need to add some kind of rule constraint to a recognised entity validation will be pretty common - and a lot of these rules (like this GS1 rule) might be of the cross-property rule type that cant be specificed in JSON schema. WOuld it make sense to allow an array of rule expressions as well as the schema - eg using CEL &nbsp;|&nbsp; Common Expression Language

Manu_Sporny: Bs. Yes. Thank you. That is exactly the type of adjustments I'm looking for in the PR. please if you can make a note of that, I missed that on the first read through. Great. Todd Snyder:

Todd_Snyder: I did too. but the concept I think Steve put it in the chat too that this is a common pattern. We just need to figure out the right mechanism and the JSON schema seems like a good place to kind of start and then as Phil was saying we need to work with our take this and then put it into our world and kind of work through the use cases and verify that we're covering everything we need to do and it works. but I think what you have here is is a good foundational piece.

Manu_Sporny: Okay, great. Thanks, Todd. Phil, you're up.

Phil_Archer: Just very briefly, clearer.

Phil_Archer: I think Todd, you and I need to get some time together. Certainly you and me, ideally with Paul, as soon as I think we should work through this, as you just said, and offer something back as well. I think if we do that, that will help everybody be much clearer.

Manu_Sporny: Yes, definitely. Plus one to that, Phil. …

Phil_Archer: Just for everybody who doesn't already know this to give some weight behind this that sorry, am I breaking up again? Sorry. Sorry.

Manu_Sporny: a little

Phil_Archer: I apologize. I really should I know it's so convenient to be able to walk the dog while I'm in this call on a Tuesday night at 9:00. I'm sorry. I just wanted to tell everyone by the way that this is a very real thing we're talking about here that base did VC issuance system exists. That route did exist. There are two sets of three people that you need to be able to use that. I am one of the three people in one of those sets. The other three people are the office holders of the organization. This is a very very real use case that's coming out in the real world and…

Phil_Archer: everyone has been involved in this. Thank you.

Manu_Sporny: Thank you, very exciting that this stuff's moving forward. go ahead, Steve. You're upon

Steve Capell: Yeah, thanks.

Steve Capell: Just thinking about these validation rules and again accepting that there's a line to be drawn somewhere between what's in the spec and what isn't. But there's a lot of rules which are a kind of if this field has this subset then and matches this one then true that are not really supported natively by JSON schema. so the question is do we leave nowhere for them in the spec?

Steve Capell: Do we say you can always extend a JSON schema but then the processor needs to know about those extensions or do we say as well as the schema validation here's a list of expressions you should run and then you get into what expression language there are some candidates but I think it's not uncommon to need to separate rules from structure right so for example an invoice schema you might actually have one not too complicated invoice schema, but you might have hundreds of validation rules that are outside the schema about if it's an Australian invoice, then the business identifier must be an Australian business number.

Steve Capell: these sort of things. The European road transport there's a consortium called EFTI that is trying to make road consignment nodes, digital ones for trucks moving around Europe. And they had one schema, but now they've got something like 130 schema because of little country specific tweaks. And I feel like they've got their architecture that they need to separate the rules from the schema. So that's a long way of saying I think it's not uncommon that there would be a schema defining structure and then separately some rules to evaluate over the instance that conforms to the schema. And if you had that structure here, you'd meet the GS1 use case with some sort of expression that says the first six characters of this field must match the full string of that field.

Steve Capell: And is it worth putting placeholders in there? I don't know. But I'd be a bit cautious about blending it in with the schema because then it becomes an kind of an invisible thing that a processor might not know how to deal with.

Steve Capell: A shackle possibly. Yes.

Manu_Sporny: Yeah. Yeah.

Manu_Sporny: That's an excellent point, JSON schema is greatly limited, right? So we should probably say it can do a rough first approximation that your data is in the general shape you're expecting but in no way is it ever going to be able to run business even moderate to complex business rules on the credential right it can check syntax and structure and that's pretty much it.

Manu_Sporny: At that point you're into kind of executing code and…

<Ted_Thibodeau_Jr> SHACL will be your friend

Todd_Snyder: Yeah, and…

Todd_Snyder: it's very much field level. You really can't compare one field against another field even the same credential. So,

Manu_Sporny: logic and that sort of thing and that is entirely out of scope. let me it is we have to defer that to the market verticals in the specialists in the ecosystem and that sort of thing. we will never be able to come up with, generalized rules. so that's an excellent point, Steve. I think what we should do is let people know there are limitations to this. there are going to be fields that you should put into these credentials that other people are going to be using in their logic when they're trying to deter

Manu_Sporny: determine whether or not this is a legitimate credential to use. Output validation is only a pretty rough approximation. We hope that it's kind of, good good enough for a rough approximation. At which point your verifier or validation engine will be expected to run your market vertical or use case specific business rules on the data that you got into the system, so hopefully that addresses your concern, Steve, in that we should talk about it in the spec that you can't just run a JSON schema and then blindly, pull the data into your system. You've got to have some kind of business rule engine that runs over the data before you actually use it for any more serious purpose.

Manu_Sporny: Okay noting all that I'm going to keep going through the example. So this is global office effectively recognizing a member organization to issue something with a license value starting with 950 a prefix with 950 and then we go down into the member organization which is GS1 Utopia recognizing this healthy tots company who is a company that is within their jurisdiction.

Manu_Sporny: So they recognize that healthy tots and then constrain the license value to the one that is associated with healthy tots either through the JSON schema or some license value something and then the healthy tots will take that recognized entity credential and then they will issue a GS1 key credential for an actual

Manu_Sporny: G10 with a GS1 digital link identifier for Apple and carrot puree using their recognized entity credential referencing it right and so this is where you would get the GS1 digital link kind of u identifier and then be able to trace it all the way back back to GS1 one Utopia member organization and then back up to GS1 Global Office and know that the whole chain checks out and yes, this is a legitimate G10 issued by Healthy Tots. at the bottom here, we kind

Manu_Sporny: of explain that in pros. so I think that that's the entirety of it. it's the examples take up the most amount of space. The explanation is only about a paragraph per example and then we've got the diagram here. So, I think next steps here are Phil, you Todd and Paul are going to get together maybe discuss a bit, come back to us with a concrete, recommendation or just a set of questions on something that you want to kind of discuss with the group and then we'll iterate from there.

<Steve Capell> although SHACL is XML designed to work of RDF i think. not sure if theres a JSON compatible version fo SHACL

Manu_Sporny: Do you want me to hold off on pulling the PR in until after you do that or do you want to pull the PR in and then do a revision PR later? I'd like to get it in sooner than later because if we kick off horizontal review, I want them to be able to see this. I doubt they're going to look at it in the first week or two, but within the first month might be possible.

Phil_Archer: agree very much.

Manu_Sporny: That's but it's a very light preference. thoughts, Phil, Todd, go ahead, Phil. Okay.

Phil_Archer: I'd like to get this merged now. we all recognize it needs more work, which we will do over the coming weeks. It might take us two or three. Bear in mind that we're also into July and August, so a lot of people are going to be on holiday at just the wrong time. but …

Phil_Archer: yes, I agree. let's get it in there. maybe put a note on it saying something like, details being worked out or something like that. I don't know. some kind of indication that it isn't final and complain W3C or…

Manu_Sporny: Yep.

Todd_Snyder: Yeah, I think as long as we say this is Yeah,…

Phil_Archer: GS1 if this isn't right. Yeah.

Todd_Snyder: it's a work in progress. I think it's fine to merge it as is.

Manu_Sporny: I'll put in an issue marker right at the top here. it'll be big red and say that the group is continuing to refine this use case and the examples and expect updates. given that I'll merge it in after I get that marker in there. All thank you all very much. That was a great discussion. let's jump to the UN grid example which I raised this pull request 45 minutes ago one minute after the call started. So certainly nobody's been able to look at it just yet.

UN Grid Digital Identity Anchor

Manu_Sporny: But let's go ahead and start going through this. I doubt we're going to be able to get through the entire thing during this call, but Steve, we'll start off the next call with going through what we weren't able to get through. go ahead, Steve. Excellent. Mhm.

Steve Capell:

Steve Capell: I did have a quick look and I've already posted a request for the grid project lead to review it and give you comments. It's looks not bad. I would say the introductory text is a little bit too invoice specific, Because invoice is a use case of grid, but grid is generally how do I know that the authority in that other country is really the authority in that country and that's pretty much all grid is.

Add complete UN GRID example to appendix by msporny · Pull Request #104 · w3c/vc-recognized-entities · GitHub

Steve Capell: And so I would prefer an intro section that was a little bit less invoice specific, maybe referring using invoice as an example, but really …

Steve Capell: so we could either tweak that now or I'd rather say give John, who's the project lead, a few days to review your offer comments, and then merge it.

Manu_Sporny: Yeah, absolutely.

Manu_Sporny: And again, totally not, …

Manu_Sporny: wedded to any of the text in here. I just tried something and…

Steve Capell: Thank you very much for trying.

Manu_Sporny: yeah,…

Steve Capell: It is great. Manu Sporny:

Manu_Sporny: No problem. There were big numbers in here 5 billion commercial invoices and 50 million trading entities which I've heard multiple times before and those were compelling numbers. So that's why I went with this one.

Steve Capell: Yes. Yeah.

Manu_Sporny: But yeah, happy to change it to whatever John would like it changed to. and the best way would be to just propose replacement text and I'm happy to dump that into the spec. let's see. I did not look that this let me kind of go back here. So the difference with this use case is that it uses identifierbased discovery not credentialbased discovery. So the GS1 use case uses credentialbased discovery where you embed the recognized entity kind of discovery information into the credential itself.

Manu_Sporny: I started working on this one with it embedded. and then I was like yeah no they want to do it using the did and who is service who is service and I updated everything to use that instead. I think the interesting thing that I discovered in forgetting that detail is that you can actually inject the information into all of these credentials and it works just the same Steve I know I wasn't here last week but I think you had a discussion about how does discovery happen?

Manu_Sporny: should it be, credential identifier based? And it turns out that you can do it both ways. And you can also mix and…

Steve Capell: Yeah. …

Manu_Sporny: match, which I thought was, interesting. and I have no opinion on which one's better or worse, I'm just saying it looks like we've, stumbled upon a design that you can do one or the other or you can mix and match and it works just the same, right? which I thought was an interesting problem.

Steve Capell: in theory, it shouldn't matter It's…

Steve Capell: which signpost you follow to get to the city, I mean, you're landing on credentials and then you're verifying the credentials. How you found them can be many different ways. Might have arrived by carrier pigeon.

Manu_Sporny: Exactly. Yep.

Manu_Sporny: But it was kind of like a nice surprise. I wasn't expecting it to work out that okay so the current example is set up is that we have this trade document like a commercial invoice and it's issuer issued by an exporters did and it's a fairly shortlived document a couple of weeks to months and that is kind of the equivalent of the GS1 kind of G10 the key credential right so there are many of these things issued every year.

Manu_Sporny: And the exporters is the thing that matters there because that is the thing that you use to look up who is service and then go and get the set of credentials that exporter has and one of them is going to be a recognized entity credential right and then you're going to go up the chain to the national registar who knows who that exporter is and gave them a recognize entity credential that says they're recogn recognized legal entity. and then that recognized entity credential is going to have an issuing did that is going to basically point up to the UN grid international registar that attests that they know that sovereign authority is.

Manu_Sporny: Same kind of structure but the discovery mechanism is all identifier based discovery. you don't find out from just the credential alone. okay so that's what this thing kind of describes. and I tried inverting the flow for this diagram. I don't know if I really like the previous diagram with the GS1 went top down, Global office to member or to company to GS1 digital link credential.

Manu_Sporny: This one goes bottom up because that felt more natural, Steve. this is supposed to be I think kind of bottom up thing. So it goes from kind of the registered exporter issuing a commercial invoice and then what do you do from that commercial invoice? you resolve the issuers did which is the Acme exports did document. You look up who is service and then you find their recognized entity credential through the verifiable present presentation. So you go from the commercial invoice you follow it to acme did and then you get to the recognized entity credential that was issued by the utopian business registar who's the national registar right but who gave them the authority?

Manu_Sporny: Then you go to the recognized entity credential. You do the same process again. You resolve their did. who is endpoint. You get the data there and that gives you a recognized entity credential issued by UN grid the trust anchor right and then that's how you figure out yeah the chain I trust everything from the commercial invoice up to the top the other thing that I struggled with a bit, Steve, is I tried to not talk about the digital identity anchor. because I was like, let's try to see because in one of your comments you're happy to replace it if we can do it. And so I tried to do that in the narrative here and I don't know if it actually, works. So please do take a look through and see if it works out.

Manu_Sporny: So let me stop there with the diagram. It's the thing I don't like about the diagram is it's much more complicated than the other one, right? the thoughts on it,…

Manu_Sporny: Steve, or just want to kind of give it a think and come back in a week.

Steve Capell:

Steve Capell: It does look a bit more complex, but I think I kind of like the story that it's telling of the discovery path, I mean, you can look at it from the issuing perspective like the GS1. It's a top- down architecture, but you can also look at it from the verifier discovery path, which is the way you've drawn it here, then I find a link credential to that. so I wouldn't mind keeping it like this.

Manu_Sporny: Mhm. Yep.

Steve Capell: I wonder whether there's some words worth adding to say, look, because the GS11 could also be presented like this, couldn't it? Right?

Steve Capell: because I might be probably the verification path is bottom up. you could put some words to say we've shown in the GS1 thing the top down issuing kind of governance structure if you like and in the grid one a bottomup discovery but they're just different views of the same thing. I don't mind it. I've just put a comment in your PR that actually just a couple of words at the beginning would probably make it good enough to merge for

Steve Capell: now and then let the team offer you suggest changes.

Manu_Sporny: Okay.

Manu_Sporny: All right. Yeah. Yeah. and again totally not tied to this. I was just experimenting and trying a different view and you're right this is very much verifier driven discovery and…

Steve Capell: I'm very grateful you made the time to do it.

Manu_Sporny: going through that process. No problem.

Steve Capell: I don't know how you find hours in a day.

Manu_Sporny: Happy all right. let's see. So, the rest of it is, and we've got four minutes left. it looks like I broke a link to the, documentation. I'll fix that. so this is recognized the UN grid recognizing the national business register and it's the same kind of thing right it's like here's the grid they are recognizing the utopian business register to issue a entity recognition credentials. I was struggling a bit here as well, Steve. I was kind of like,…

<Ted_Thibodeau_Jr> SHACL is not XML. SHACL is about validation of RDF graph shapes. SHACL 1.2 is now in progress at GitHub - w3c/data-shapes: Data Shapes WG repo · GitHub

<Todd_Snyder> In the JavaScript world SHACL has never caught on. We GS1 end up using extended json schemas and custom code to verify our chain.

Manu_Sporny: what exactly would the schema do? So I think there's stuff that I need to think about that a bit more like what would the schema actually look like or…

Steve Capell: Yeah, I'm not sure there would be a recognized two.

Manu_Sporny: do we actually need to do a bit more in the credential that's issued they're gonna go ahead.

Steve Capell: You might even just remove that section. because it's really because …

Manu_Sporny: Sorry, Steve.

Steve Capell: if you think about the business architecture here the business register is asserting that you are this registered business.

Steve Capell: It's in no position to say you are allowed to issue invoices or…

Steve Capell: way bills so I don't think there is any sort of construct of recognized to it's only recognized in

Manu_Sporny: So I…

Manu_Sporny: but let's see the construct and this might be wrong Steve right so the construct right now is the when global register is saying that they're allowed to recognized entity recognition credentials and in the JSON schema it might say that they're only allowed to issue them for a particular nation right like the credential that they issue needs to have a field in it that says specifically that this business is an Australian business right so if look at Australia.

Manu_Sporny: So, Grid would issue, the Australian Business Register something that says, " they can issue recognized entity credentials, but in their recognized entity credentials, it must state that the company's address is an Australian address,…

Steve Capell: All right.

Manu_Sporny: if that makes sense. that's I think missing from this right now that need to think a bit more about. what would the Australian business register issue and that I think is the thing that goes in the recognized too. And I get…

Steve Capell: Okay.

Manu_Sporny: what you're saying we could decide not to not put this in here and…

Manu_Sporny: just say yeah they're recognized but then some of the logic gets pulled out into outofband stuff right and I think we're trying to put as much inband as makes sense…

Steve Capell: Have you put anything?

Manu_Sporny: but understanding go ahead Yes.

Steve Capell: I just want to look at the other credential, the one issued by the registar to the business. Does it have a recognized two or is it just

Manu_Sporny: I mean it has a recognized to issue commercial invoices, So then I don't know if that's right either. I mean they are an export company and maybe the Australian register knows they should be doing that.

Steve Capell: Yeah. Yeah.

Steve Capell: But I don't think if the principle is this should reflect a governance architecture that the company's registers companies. It doesn't say as a company you can do this or…

Steve Capell: do this or do that in terms of transactions, right? there's just nothing. It kind of makes no sense.

Manu_Sporny: Yeah. So maybe this is…

Manu_Sporny: where it's like this doesn't make any sense to have recognized two at this level. It's just you're the company and here's your ID.

Steve Capell: Yeah, I think so. Yeah.

Manu_Sporny: The end. Okay, That's great feedback. I'll try to fold that in. we are out of time for today. we'll pick it up next time and keep going through this so that we can do some refinement.

Manu_Sporny: Steve, I was going to let this hang out for a week unless you're like, "No, let's get this in here and then we can revise." Okay.

Steve Capell: I know you can leave it for a week.

Steve Capell: I've written to John to say have a look offer his comments.

Manu_Sporny: Okay.

Steve Capell: Okay. Cool.

Manu_Sporny: Because there's at least two more passes I want to do on this to feel a bit better about it before merging. That's it for the call today. Thank you everyone very much for all the work to get us here.

Manu_Sporny: We will get those horizontal reviews kicked off this week and we will meet again next week. Thanks all. Have a good night. Take care. Bye.

Phil_Archer: Thanks M.

Phil_Archer: Things that are done. Meeting ended after 01:00:11 👋 This editable transcript was computer generated and might contain errors. People can also change the text after it was created.

<Ted_Thibodeau_Jr> Also see Data Shapes | Working Groups | Discover W3C groups | W3C

<Ted_Thibodeau_Jr> If there are reasons you know of that have prevented uptake in the JS world, we'd more than welcome your input! (Yes, I'm also in the data-shapes WG.)

This transcription was generated by a large language model (LLM) and might contain errors. When in doubt, check the audio recording. This page was formatted by scribe.perl version 248 (Mon Oct 27 20:04:16 2025 UTC).