The Missing Layer Behind Digital Trust
What a recent paper on digital identity governance gets exactly right and what it unintentionally reveals.

Every so often I read a paper that leaves me thinking long after I’ve finished it. Not because I disagree with it, but because it has illuminated a problem so clearly that it points toward an even deeper one. Strategic Identity Asymmetry is one of those papers.
The paper examines why digital identity systems continue to struggle with interoperability despite decades of investment in cryptography, public key infrastructure, biometrics, digital credentials, and privacy legislation. Looking across several national identity programs, the authors conclude that governments consistently invest in the visible technical infrastructure while underinvesting in governance, accreditation, and assurance. The result is a world in which countries can issue highly sophisticated digital credentials that nevertheless struggle to be trusted or recognized beyond their own borders. It is an insightful diagnosis and, I believe, largely correct. Yet while reading it I found myself repeatedly asking a different question. A question that never quite appears in the paper itself.
The paper speaks often of trust, governance, assurance, accreditation, and interoperability. It asks how trust can be exported across jurisdictions and how credentials issued in one country might be recognized in another.
But beneath all of these questions lies another, more fundamental one that is never explicitly articulated:
Who controls the record?
That question may seem almost too simple to matter. Yet I increasingly believe it is the missing architectural concept behind much of today’s thinking about digital trust.
It is easier to view from the point of view of digital trade. Suppose Brazil issues a digital warehouse receipt that is later presented in another jurisdiction. The paper naturally asks whether Brazil’s governance framework should be trusted and whether its assurance mechanisms are sufficient to justify recognition. Those are important questions, but they are not the first questions. Before another jurisdiction decides whether to recognize the record, it must first determine something much simpler: who currently controls it? Has control been transferred? Has it been delegated? Has it been revoked? Only once those questions have been answered does governance become relevant. Governance determines whether a control relationship should be recognized. It does not create the control relationship itself.
This distinction is subtle, but I believe it explains why so many digital identity architectures have become increasingly complex. Without an explicit concept of control, governance is asked to do too much. It becomes responsible not only for determining who should be trusted, but implicitly for determining who controls the underlying record. Recognition and control become fused into a single architectural concern.
Over the past year I have been exploring what I call the Three-Layer Model. You can read all about it in a recently published paper, Control is the Operative Fact. The model begins with a simple observation: digital systems answer three fundamentally different kinds of questions. At the Protocol Layer, systems establish correctness. They determine whether signatures verify, whether events occurred, and whether records have been altered. At the Recognition Layer, legal systems, institutions, regulators, and markets determine meaning, authority, rights, and legal effect. Between them lies a third concern that has largely remained implicit. The Control Layer answers a different question entirely: who controls what?
Once this distinction becomes visible, many long-standing problems begin to look different. Protocols establish facts. Recognition assigns meaning. Control establishes the relationship between a controller and a record. Each layer performs a distinct role, yet modern digital identity systems frequently attempt to collapse all three into a single architecture. Public keys become identities. Identities become trust anchors. Governance frameworks become mechanisms for establishing control. The resulting complexity is perhaps less surprising than inevitable.
One phrase in the paper particularly caught my attention. The authors describe the challenge as one of enabling countries to “export trust.” I wonder whether trust is actually what crosses borders.
When a bill of lading moves between jurisdictions, trust is not what moves. When a warehouse receipt changes hands, trust is not transferred. When a negotiable instrument is endorsed, or a digital asset is conveyed, the thing that moves is a control relationship. Recognition follows later, when a court, regulator, bank, or counterparty decides whether to give legal effect to that relationship. Trust, in the end, is the judgment made by the observer. Control is the thing being observed.
That distinction has become increasingly apparent in commercial law. The English Law Commission recognized that many digital assets fit neither the traditional category of things in possession nor things in action, pointing instead toward a third category defined by factual control. UCC Article 12 built upon a similar insight through its introduction of the Controllable Electronic Record. The law is gradually shifting from possession toward control, not because technology demands it, but because possession was always an imperfect proxy for the more fundamental concept of control.
Viewed through that lens, the governance challenges described in Strategic Identity Asymmetry appear in a different light. Rather than exposing a deficiency in governance alone, they may be exposing the absence of an explicit model of control. Governance remains essential, but it operates on top of control relationships rather than creating them. Recognition gives those relationships legal and institutional effect. Protocols provide the cryptographic evidence. Between them lies the architecture that connects the two.
None of this should be read as a criticism of the paper. On the contrary, I think it identifies one of the most important challenges facing digital identity today. My only suggestion is that the missing ingredient may not be another governance framework or another assurance model. It may be the recognition that control itself deserves to be treated as a first-class architectural concept.
Perhaps the next evolution in digital trust will not come from building ever more elaborate systems of recognition. Perhaps it will come from asking a much older question that societies have been answering since the days of Yap stones, tally sticks, negotiable instruments, and bearer bonds.
The next time you encounter a new digital asset, identity system, credential, or blockchain protocol, resist the temptation to begin with questions of governance or trust. Start instead with the more fundamental question: Who controls the record? You may be surprised how quickly the underlying architecture reveals itself once you ask that question.

As always, Tim, you cut right through the noise and get to the heart of the issue.
Thank you for writing this. It hit home.
The line that stayed with me was the distinction between trust, recognition, and control. “Who controls the record?” feels like the question many digital identity, trade, and blockchain systems keep circling without naming directly.
You may find this related Frontiers article useful: Issam Najati’s 2025 piece on TradeLens through the lens of commons theory. It examines why blockchain supply-chain platforms can fail even when the technical infrastructure works: unclear governance, weak participation, interoperability gaps, and unresolved questions around shared resources.
I think your control framing and the commons lens belong in conversation. Commons theory explains the institutional environment around the shared record. Your essay names the operative fact inside it.
Appreciate the piece. It sharpened the problem for me.
https://www.frontiersin.org/journals/blockchain/articles/10.3389/fbloc.2025.1503595/full