Skip to content
ADR-0022Architecture decisionAcceptedversion 1.0.02 October 2026

Context ​

ADR-0011 registered the Tamga identity service in the güven listesi (trust list)Bir ülkenin kök sertifikalarını, belge verenlerini ve kayıtlı relying party'lerini taşıyan imzalı liste. Bugün Tamga'da güven bu listelere dayanır; ortak defter sonra gelir. as class: QUALIFIED, assurance: I3; the identity credential carries category: urn:tamga:eaa:qualified, and the schema requires it as a fixed value.

The EU gap analysis (2026-09-29) and the code comparison of 27 September (finding K5) showed:

  • In eIDAS (electronic IDentification, Authentication and trust Services)AB'nin elektronik kimlik ve güven hizmetleri tüzüğü; eIDAS 2.0 Avrupa Dijital Kimlik Cüzdanı'nı getirir. 2.0 "qualified" (QEAA (Qualified Electronic Attestation of Attributes)Nitelikli güven hizmeti sağlayıcısının (QTSP) verdiği EAA; attestation'lar arasında hukuki etkisi en güçlü olandır. / QTSP (Qualified Trust Service Provider)eIDAS kapsamında ulusal denetim kurumundan nitelikli statü almış güven hizmeti sağlayıcısı.) is a legal title. It requires an audit by an independent conformity assessment body and supervision by the supervisory body.
  • FW-TF-0001 ties I3 to the condition of an "independent assessment".
  • Tamga is at the same time the list operator, the registrar and the identity service. It registered itself in the highest class; there is no independent assessment. The remote identity verification provider's conformity with ETSI TS 119 461 is at the level of a declaration.

When talking to the EU side this reads as an overstated claim; it carries legal and reputational risk.

Decision ​

K1 — Class and assurance ​

The Tamga identity service is registered in the trust list as class: EAA (non-qualified electronic attestation of attributes, EAA (Electronic Attestation of Attributes)Kişinin bir özniteliğini (diploma, üyelik gibi) doğrulayan belge için eIDAS'taki ad.) and assurance: I2.

K2 — No category in the credential ​

The identity credential (urn:tamga:id:IdentityAttestation:1) carries no category claim (ADR-0010 K5: the category is only for PUB / QUALIFIED belge veren (issuer)Belgeyi imzalayıp veren kurum: üniversite, meslek kuruluşu, kamu kurumu ya da şirket.s). The minimum issuer assurance in the schema metadata goes down from I3 to I2.

K3 — Policies that use it ​

Policies that request the identity credential (institutions' identity matching, sample sites) require a minimum issuer assurance of I2.

Identity verification itself does not change:

  • document + liveness + face matching,
  • optional NFC chip reading,
  • HMAC document digest.

Only the label in the trust list is brought in line with reality.

K4 — Raising it again ​

Once an independent conformity assessment (within ETSI TS 119 461 / TS 119 471) is done and the FW-TF-0001 I3 conditions are met, the class is raised by a new ADR.

K5 — In-place correction before the pilot ​

The schema 1.0.0 metadata is corrected in place because we are before the pilot (the same one-time exception as the English correction of 2026-09-29). Existing test identity credentials are re-issued. In the pilot the D1 immutability rule applies unchanged.

Options considered ​

OptionResultWhy
Staying at QUALIFIED / I3rejectedNo independent assessment; the claim of "qualified" in the EU sense cannot be met
QUALIFIED, I2rejectedThe class name is still confused with the EU legal title
EAA, I2acceptedDescribes the real situation; in the EU a non-qualified EAA can be issued by anyone
EAA, I1rejectedIdentity verification and key management meet the I2 conditions

Invariants ​

CodeRule
IDC1A service operated by Tamga itself is not registered in the trust list as QUALIFIED or I3 without an independent conformity assessment.
IDC2The identity credential carries no category claim; until the class is raised, no policy requires I3 for the identity credential.

Consequences ​

  • apps/trust-publisher/registry/tl-tr.source.json: tamga-id → class: EAA, assurance: I2.
  • packages/schemas: the IdentityAttestation category field is removed, min_issuer_assurance: I2 (1.0.0 in place).
  • apps/id (operator repository): no category is written into the identity credential. apps/issuer: identity matching policy I2.
  • The class line of ADR-0011, SPEC-ID-0003, FW-RB-0001 RB-AP-ID-04 and the Identity Rulebook are updated.

Status ​

Accepted — 2026-09-29. With project management approval. DECISIONS: D-ID-7.