Trust network
User-facing documentation for Community OS: guides, concepts, references, and technical material.
By type
By domain
Trust network
- What is a Personal Data Server (PDS)
- How DID resolution works
- How delegated authority is represented
- Roles in the trust network
- Permissions in Community OS
- Record statuses in the trust network
- Become a trustee
- Accept an invitation
- Delegate authority
- Grant consent
- Set up a support arrangement
- Access a support plan
- Review and revoke consent
- Resign as a trustee
- What is a trustee
- What is delegated authority
- What is consent
- What is a support arrangement
- What is a DID
All docs
- What is a Personal Data Server (PDS)Technical
A Personal Data Server (PDS) is the online service that stores and serves one person's records. It holds the person's repository and answers requests for the records in it. In Community OS, the records that name a person, such as their support plan, delegations, and consent grants, live in that person's own PDS repository.
- How DID resolution worksTechnical
A DID is a permanent digital address. DID resolution is the process that turns that address into the current details of the person, organisation, or service behind it. When a record names someone by their DID, the system resolves the DID to find where that person's records live and how to reach them.
- How delegated authority is representedTechnical
Authority in the trust network is represented as data, not as a fixed list of roles. Three kinds of record describe who may act for whom, over which records, and until when. The system reads these records at every access decision.
- Roles in the trust networkReference
This reference lists the roles in the trust network, what each role can do, and who holds the role in practice. Use it to decide who needs which role, and what that person can do with records.
- Permissions in Community OSReference
This reference explains the permission vocabulary. A permission names what one thing an account can do with one kind of record. Use it to understand why an account can or cannot take an action.
- Record statuses in the trust networkReference
This reference lists the record statuses in the trust network. A status tells you whether a record is in effect now. Use it to check why a record grants or denies access.
- Become a trusteeGuide
A beneficiary chooses the people they trust. When Wiremu chooses Hana to act for him, Hana becomes a trustee. A trustee acts for the beneficiary within set limits, called a scope. The scope names the records the trustee may work with, such as the support plan.
- Accept an invitationGuide
A beneficiary who wants you to act for them sends you an invitation. The invitation names you as a delegate on a delegation record. Accepting the invitation makes you a trustee. You are not required to accept. You decide.
- Delegate authorityGuide
Delegating authority means giving a trustee the power to act for you on a scope of records. A scope names the records, such as your support plan. You choose the trustee, the scope, and the dates. You keep control. A delegation alone does not let the trustee see anything. Your consent is always needed too.
- Grant consentGuide
Consent is your permission for someone or an app to access a collection of your records. A collection is a set of records, such as your support plan. You choose who gets access and at what level. Read means they can view. Write means they can view and change.
- Set up a support arrangementGuide
A support arrangement is the record that assigns a support worker to a beneficiary for a set period. It names the beneficiary, the support worker, the organization, and the role. It has a start date, an end date, and a status.
- Access a support planGuide
A support plan is the beneficiary's record of their goals, preferences, services, and appointments. Examples of preferences are accessibility needs such as braille. Examples of services are personal care.
- Review and revoke consentGuide
Consent is your permission for someone or an app to access a collection of your records. You can review your consent grants at any time. You can revoke one to stop access. Revoking consent stops access immediately.
- Resign as a trusteeGuide
As a trustee you act for a beneficiary within set limits. You are not forced to keep the role. You can resign at any time. Resigning means ending your delegation. After you resign, the delegation is revoked and you lose access to the beneficiary's records.
- What is a trusteeConcept
A trustee is a person a beneficiary trusts to act for them within set limits. The beneficiary chooses their trustees. A trustee is not an employee and not a stranger. A trustee is someone the beneficiary knows and relies on.
- What is delegated authorityConcept
Delegated authority is the power a beneficiary gives a trustee to act for them. The beneficiary decides the limits. The trustee acts only within those limits.
- What is consentConcept
Consent is a beneficiary's permission for someone or an app to access a collection of their records. It is the beneficiary's choice, recorded in a consent grant. It is never assumed and never implied.
- What is a support arrangementConcept
A support arrangement is the record that assigns a support worker to a beneficiary for a set period. It makes the working relationship formal and time-bound.
- What is a DIDConcept
A DID is a Decentralized Identifier. It is the permanent digital address of a person, an organization, or a service in Community OS. Every record that names someone uses a DID.