Consent & Privacy Service  ·  View 21 of 22  ·  Assurance

Identity & Authorisation Flow

An agent acting for a caller, and the one message that keeps the identity graph out of their hands.

Editable source SVG draw.io All views
Subject on the phone Support agent Agent console Workforce IdP Case intake Identity resolver Audit store 1. "delete my account" 2. open a case 3. step-up, agent role 4. assertion, 30 min 5. create case (acting for) 6. verify the caller 7. one-time code 8. code 9. resolve, case-bound 10. scope to this case 11. identifier set 12. case open, fields masked 13. who, what, for whom 14. every record read 15. access expires in 30 min Identity & Authorisation — An Agent Acts On a Caller's Behalf The agent never holds standing access. Message 10 is the control: the resolver answers only for the identifiers this case needs, and logs each one. v 1.0 · owner Security & Identity Architecture

Decisions

  • Verification is proportionate to the request and recorded on the case: session authentication for a preference change, step-up and a one-time code to the subject for an erasure.
  • Message 10 is the control: the resolver scopes its answer to this case's needs and audits each record read. The agent sees a case, not a person's graph.
  • The agent's own authorisation is a 30-minute assertion naming the role and the case. Nothing here grants standing access to anything.

Assumptions

  • Workforce identity federated into a case-bound role; the agent console shows masked fields by default.
  • Every caller is a workload identity bound to a registered system and may evaluate only the purposes it is registered against.

Risks

  • A social-engineered agent is the most likely route to a wrongful erasure. The one-time code to the subject is the control, and it is the step most likely to be waived under service-level pressure.
  • Auditing every index read is a volume cost that will be questioned. It is the only evidence that the index was not browsed.