The operator
Your organisation on the record
Every Passport names an operator. That operator relationship is the Parent, and it is the only part of the record independent verification can ever strengthen — never the device.
DECLARED
Every Passport starts with a free DECLARED Parent
What DECLARED means
Self-declared organisation identity. Not independently verified. It is the honest floor, published with its date so a reader can weigh it for themselves.
What it is already enough for
Holding every free Passport in every family, publishing its record, adding bindings, and being resolved by anyone. No verification is required to hold an identity.
Optional
Parent VERIFIED and ASSURED
The boundary
It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID.
Included free: Every Passport starts with a free DECLARED Parent — created for you if your organisation has none.
The boundary that matters most
Verifying the organisation does not verify the subject
This is the distinction a reader is most likely to collapse, so the record keeps them apart: the Parent’s assurance state and the child’s are two separate fields, and a machine reading the record sees them separately too. A VERIFIED Parent raises confidence in who is answering for the connected device. It says nothing about the connected device itself.
