Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Platform capability

Policy & authorization

The right identity still needs the right entitlement and context.

Policy & authorization

Target model from the specification. Actual product scope requires approval.

Identity is not entitlement

Verified identity is not automatic access. Policy evaluates resource, action, role, shift, location and risk.

A bounded decision

Use explicit ALLOW, DENY, STEP_UP_REQUIRED or HUMAN_REVIEW. Grants have scope and expiry and are bound to a specific request.

Reference implementation - Trusted PalmPay
Policy & authorization
Policy & authorizationSelect to enlarge ↗

Evaluation & evidence requirements

AreaRequirement
Context bindingOrganization, purpose, device, session and policy
Exception statesMissing data, ambiguous identity, expiry and fallback
Required evidenceVersioned report, scope, reviewer and limitations
Publication statusNo product test report supplied in the website package; deployment is not inferred.

Search Trusted Palm ID

Selected interface