Skip to content

M5-02 Disclosure Policy / Level-of-Assurance Configuration

Milestone: M5 — Disclosure and Verification SOW Reference: FR2 Requirement Clarity: 🔄 Reopened 2026-08-25 — do not treat as resolved. This was marked "✅ Resolved, MVP is one generic request" on 2026-08-20 based on that day's client feedback. A follow-up clarification call on 2026-08-25 corrected that: Org Admin does configure something after all — named "packages" combining Disclose Credentials / Right to Work / Reclaim Employment (see M5-00's update and M5-01). This is coarser than the SOW's literal "per-credential-type policy," but it is real, admin-facing configuration — the opposite of "no config needed." The original blocking question (default-only vs. fully configurable identity-assurance policy) is still not directly answered; it's just now clear the answer isn't "nothing to configure." Dev Status: ❌ Not started

Overview

Configure what level of assurance / what data a Relying Party requires an individual to share when disclosing credentials, mirroring the policy capability in the Velocity Credential Agent. Updated 2026-08-25: in practice, MVP-level "policy" is package selection (which atomic request types — Disclose/RTW/Reclaim — are bundled together), not a granular per-credential-field assurance level. Confirm this is what "policy" means for MVP before reading the rest of this file's original (now likely overtaken) backend-task framing as still current.

Backend Tasks

  • First: get written confirmation from Curo on scope — default-only (matches original MVP intent) vs. fully configurable (matches SOW literal text) vs. the now-clarified middle ground (package-level configuration only, per M5-00/M5-01)
  • If package-level (current best understanding): build the package model described in M5-01 — org-defined named combinations of Disclose/RTW/Reclaim, not per-field assurance levels
  • If default-only: hardcode a single sensible default policy (e.g. email verification) across all organisations
  • If fully configurable: build a policy model + admin UI to define required disclosure fields per organisation, and pass that policy through to the Velocity Credential Agent's disclosure configuration

Frontend Tasks

  • Package configuration UI under org settings (see M5-01) — current best understanding of what this task actually is for MVP
  • If fully configurable beyond packages: build the deeper policy admin page under org settings

Dependencies

Acceptance Criteria

  • Velocity policy configuration can be created (per SOW Appendix 3, FR2 acceptance criteria) — note the criterion itself doesn't specify depth, which is exactly the ambiguity to resolve.

Existing Reference Material

Blockers & Risks

  • Blocking: effort estimate for this task (and by extension M5/M6 as a whole) cannot be finalised until scope is confirmed.