Manifesto

Human identity needs a consent protocol.

Face, voice, likeness, motion, style, and work are becoming programmable. Permission has to become programmable too — without making every app the custodian of a person's raw identity.

The current system was built for slower media. It relies on contracts, policy pages, platform moderation, screenshots, takedowns, and litigation after harm has already happened. That is too slow for products that can display, edit, generate, publish, verify, distribute, or monetize identity instantly.

DIAP — the Digital Identity Authorization Protocol — is the missing control plane. It is not an image model, a voice model, a talent agency, a studio-only compliance dashboard, or a rights marketplace. It is the neutral authorization layer that answers a practical question before a system acts: is this use of this human-linked identity module allowed, for this product, this project, this action, this output, and this time window?

The protocol treats human identity as modular because real products do. A studio may need motion capture and face render approval. A creative SaaS app may need an avatar preview. A voice-agent company may need a synthesis grant. A marketplace may need listing visibility. A social platform may need watermark verification. A game engine may need athlete likeness and motion scope. These are not the same right, and a single vague checkbox cannot govern them.

DIAP separates three decisions that are usually collapsed: visibility, authorization, and proof. Visibility says whether a module may be discovered, shown, searched, selected, or previewed. Authorization says whether a specific use is allowed. Proof says what actually happened after the use: token, receipt, output hash, watermark, distribution surface, and revocation state.

The protocol also needs a human-facing home. That is the role of diap.my.id: secure hosted identity-vault infrastructure that any SaaS product, editor, marketplace, model provider, social platform, enterprise tool, game, agency, or studio can integrate into its own experience. Their users get vaults, visibility controls, approvals, receipts, delegates, and revocation; the partner product gets API decisions and proof without becoming the custodian of raw identity data.

The intended default is simple: no system should use human identity without a verifiable grant, and no grant should be trusted without scope, expiry, revocation, and receipt obligations that machines can enforce.

Consent first

A system should check permission before using human identity, not apologize after the output spreads.

Scope matters

A face render, voice reference, motion capture pass, training run, endorsement, edit, listing, and public release are different permissions.

Visibility is not permission

Being discoverable in a product, search result, casting roster, marketplace, model picker, or studio tool never equals authorization to use.

Revocation is normal

Consent can change. Future use must stop when a grant expires, is revoked, or no longer matches the approved scope.

Proof travels

Tokens, receipts, signatures, and watermarks let platforms, distributors, users, and auditors verify authorization after the content leaves the original app.

Custody should be minimized

Products should not need to store raw face, voice, likeness, motion, style, or authorship data just to do the right thing.

Open protocol

DIAP is for any product that can display, edit, generate, publish, verify, distribute, or monetize human identity: editors, social platforms, model providers, marketplaces, enterprise tools, games, studios, and agencies.

Humans stay legible

The person whose identity is involved should be able to see requests, approve or deny scope, inspect receipts, delegate review, and revoke future use.

The runtime DIAP wants every product to share

Before use

Check visibility, request a scoped grant, verify the token server-side, and fail closed on uncertainty.

During use

Keep the operation inside the approved action, module, project, medium, territory, duration, and constraints.

After use

Submit a receipt with output hash, watermark handle, model/tool context, distribution URL where applicable, and signed proof.

After revocation

Stop future use, stop pending operations, remove or label downstream surfaces as policy requires, and preserve the audit trail.

What success looks like

A creator connects a DIAP vault to an editing tool and approves only campaign previews, not training. A studio requests a Marvel-style production grant for face render, voice reference, motion capture, and trailer distribution, then submits a render receipt. A voice platform sees that a private voice module is hidden and cannot clone it. A marketplace lets a seller list only the modules the vault makes visible. A distributor verifies the watermark and receipt before monetization.

None of those products need to invent a separate consent system. None should need a copy of the person's raw identity files by default. They should call the same protocol, receive the same kinds of decisions, and leave behind proof that can be inspected later.

The goal: make authorized identity use easier than unauthorized use.