ACTOR TRUST CONTEXT
Who is acting, under whose authority, on which thing and with what evidence?
The portal is an experience surface on top of the shared trust service.
IDENTITYNo identity required for public DPP; authenticated identity
for restricted views
ORGANISATIONOrganisation context when access is role-based
ASSURANCERisk/policy-selected
MANDATERequired only for protected fields/actions
THINGOfficial carrier → resolved product / DPP
ACTIONView public or policy-composed restricted data
AUTHORITYEconomic operator / external registry / other domain
authorities
EVIDENCEResolution and disclosure decision evidence
Access rule: Public/low-risk reads do not require identity by
default; privileged, restricted or state-changing operations require policy-qualified actor context.