Comprehensive Explanation
QVI Authorized Representative (QAR)
Official Definition
A QVI Authorized Representative (QAR) is formally defined within the vLEI Ecosystem Governance Framework as a designated representative of a Qualified vLEI Issuer (QVI) who has been specifically authorized to:
- Conduct QVI operations with GLEIF (Global Legal Entity Identifier Foundation)
- Interface with Legal Entities on behalf of the QVI
- Execute operational activities related to credential issuance and management
- Perform identity verification requirements for issuing QVI vLEI Credentials
Official Abbreviation: QAR
Canonical Source: Draft vLEI Ecosystem Governance Framework Glossary (version 0.9, dated February 7, 2022), published by GLEIF
The term refers to both the designated representative (the person holding authorization) and the role itself within the vLEI governance structure. This dual nature is critical—a QAR is simultaneously an individual identity and a functional role within the credential issuance infrastructure.
Governance Context
Position in vLEI Ecosystem Hierarchy
The QAR occupies a critical intermediary position in the vLEI trust hierarchy:
GLEIF Root of Trust
↓
GLEIF External Delegated AID (GEDA)
↓
Qualified vLEI Issuer (QVI)
↓
QVI Authorized Representative (QAR) ← YOU ARE HERE
↓
Legal Entity vLEI Credentials
↓
Role Credentials (OOR/ECR)
The QAR serves as the operational executor of the QVI's delegated authority. While the QVI organization holds the contractual relationship with GLEIF and the cryptographic authority through its AID (Autonomic Identifier), the QAR is the human representative who performs the actual credential issuance operations.
Relationship to GLEIF Governance
QARs operate under the authority of GLEIF's root governance, which establishes:
- Qualification Requirements: QVIs must undergo formal qualification processes (Annual vLEI Issuer Qualification) before their QARs can operate
- Delegation Model: QVI AIDs are delegated from GLEIF's GEDA (GLEIF External Delegated AID)
- Revocation Authority: GLEIF retains the ability to revoke QVI credentials, which terminates QAR authority
- Grace Period Management: QARs must manage a 90-day grace period when QVI credentials approach expiration
Multi-Signature Group Participation
QARs typically participate in multi-signature groups that control the QVI AID. According to the governance framework:
- Minimum 2 QARs must form the multi-sig group for a QVI
- 2-of-N signature threshold is required for QVI operations
- Each QAR maintains their own AID and keystore
- QARs must perform OOBI (Out-Of-Band Introduction) exchanges with each other
- Challenge-response authentication is required between QARs using KERI protocols
This multi-signature requirement ensures that no single QAR can unilaterally issue credentials, providing operational security and accountability within the QVI organization.
Roles & Responsibilities
Primary Operational Responsibilities
1. Legal Entity Identity Verification
QARs must verify the identity of Legal Entities requesting vLEI credentials:
- LEI Validation: Verify that the supplied LEI (Legal Entity Identifier) corresponds to the requesting entity
- LEI Status Verification: Confirm LEI Entity Status is Active
- Registration Status Check: Ensure LEI Registration Status is Issued, Pending Transfer, or Pending Archival in the Global LEI System
- No Authentication Required: Notably, identity authentication is not required at the Legal Entity level for credential issuance—only identity assurance
2. Legal Entity Authorized Representative (LAR) Verification
QARs inherit LAR identity assurance and authentication requirements from the Legal Entity vLEI Credential Governance Framework:
- Identity Assurance: Verify LAR identity to at least Identity Assurance Level 2 (IAL2) per NIST 800-63A
- Real-Time OOBI Sessions: Conduct supervised remote sessions with continuous audio/video presence
- Challenge-Response Protocol: Execute cryptographic authentication using unique Challenge Messages
- Manual Credential Verification: Visually verify legal identity credentials during live sessions
3. Role Credential Issuance
QARs issue two types of role credentials:
Official Organizational Role (OOR) Credentials:
- For individuals in official positions (CEO, CFO, Board Members)
- Requires verification of official role within Legal Entity structure
- Must reference OOR Authorization vLEI Credential from LAR
Engagement Context Role (ECR) Credentials:
- For individuals in functional or engagement-specific contexts
- Does not require official organizational position
- Must reference ECR Authorization vLEI Credential from LAR
4. Credential Lifecycle Management
QARs manage the complete credential lifecycle:
- Issuance: Create and sign ACDC (Authentic Chained Data Container) credentials
- Registry Management: Anchor credentials to TEL (Transaction Event Log) registries
- Status Tracking: Monitor credential validity and expiration
- Revocation: Execute credential revocation when authorized by LARs or required by governance
Authority and Permissions
Delegated Authority from QVI
QARs exercise delegated authority from the QVI organization:
- Signing Authority: QARs can sign credential issuance events on behalf of the QVI AID
- Registry Operations: QARs can perform TEL operations for credential status management
- OOBI Publication: QARs can publish OOBIs for QVI discovery
- Witness Coordination: QARs interact with witness pools for KEL (Key Event Log) validation
Multi-Signature Constraints
QAR authority is constrained by multi-signature requirements:
- Threshold Enforcement: QARs cannot act unilaterally—threshold signatures required
- Rotation Authority: QARs participate in key rotation events for the QVI AID
- Delegation Approval: QARs must coordinate with GLEIF Authorized Representatives (GARs) for delegation approval
Interaction with Legal Entities
QARs have specific permissions when interacting with Legal Entities:
- Credential Requests: QARs can receive and process credential issuance requests from LARs
- Identity Verification: QARs can conduct identity assurance procedures
- Authorization Validation: QARs can verify QVI AUTH vLEI Credentials from LARs
- Presentation Acceptance: QARs can accept credential presentations for verification
Limitations and Constraints
Governance-Imposed Limitations
- No Unilateral Issuance: QARs cannot issue credentials without proper LAR authorization via QVI AUTH vLEI Credentials
- No Direct Legal Entity Credentials: QARs can only issue credentials to Legal Entities that have contracted with their QVI
- No Cross-QVI Operations: QARs cannot issue credentials on behalf of other QVIs
- Grace Period Constraints: QARs must manage credential transitions within the 90-day grace period
Technical Limitations
- Multi-Sig Dependency: QARs cannot perform QVI operations without threshold signatures from other QARs
- Witness Requirements: QARs must maintain connectivity to the QVI's witness pool
- Schema Compliance: QARs must issue credentials conforming to official ACDC schemas
- Registry Anchoring: QARs must anchor all credentials to appropriate TEL registries
Identity Verification Limitations
- IAL2 Minimum: QARs cannot issue credentials without meeting minimum IAL2 identity assurance
- Real-Time OOBI Requirement: QARs must conduct live video sessions—asynchronous verification is insufficient
- Challenge-Response Mandatory: QARs must execute cryptographic authentication—visual verification alone is insufficient
- No Delegation of Verification: QARs cannot delegate identity verification to third parties
Credential Lifecycle
QAR Participation in Issuance Process
The credential issuance process involving QARs follows a multi-stage workflow:
Stage 1: LAR Authorization
- LAR Preparation: Legal Entity Authorized Representatives (LARs) prepare credential requests
- Identity Assurance: LARs perform identity assurance on role credential recipients (OOR or ECR Persons)
- Authorization Credential Creation: LARs create and sign QVI AUTH vLEI Credentials authorizing the QAR to issue role credentials
- Multi-Signature Coordination: For multi-signer Legal Entities, multiple LARs must sign the authorization credential
Stage 2: QAR Verification
- Authorization Validation: QAR receives and validates the QVI AUTH vLEI Credential from LAR
- Chain Verification: QAR verifies the credential chain from GLEIF → QVI → Legal Entity → LAR
- Identity Re-Verification: QAR conducts additional identity verification of the role credential recipient
- OOBI Exchange: QAR performs OOBI exchange with the recipient's AID
- Challenge-Response: QAR executes cryptographic authentication with the recipient
Stage 3: Credential Issuance
-
ACDC Creation: QAR creates the ACDC credential with required fields:
- Issuer AID: QVI's AID
- Issuee AID: Recipient's AID
- LEI: Legal Entity's LEI
- Role Information: Official role or engagement context
- Schema Reference: SAID of the credential schema
- Edge References: SAIDs of prerequisite credentials (authorization credential, Legal Entity credential)
-
Multi-Signature Coordination: QAR coordinates with other QARs to obtain threshold signatures
-
Registry Anchoring: QAR anchors the credential to the TEL registry
-
Witness Validation: QAR ensures witnesses have validated the issuance event
Stage 4: Credential Delivery
- Presentation to Recipient: QAR presents the issued credential to the recipient
- OOBI Publication: QAR publishes OOBIs for credential discovery
- Status Verification: Recipient verifies credential status in the TEL registry
- Acceptance Confirmation: Recipient confirms acceptance of the credential
Verification Procedures
QARs participate in credential verification as issuers rather than verifiers:
- Issuer Verification: Verifiers validate that credentials were issued by a legitimate QVI with valid QAR signatures
- Chain Validation: Verifiers trace the credential chain back to GLEIF's root of trust
- Status Checking: Verifiers query the TEL registry to confirm credential has not been revoked
- Signature Verification: Verifiers validate QAR signatures against the QVI's AID key state
Revocation Conditions
QARs must revoke credentials under specific conditions:
LAR-Initiated Revocation
- Revocation Request: LAR submits a signed revocation request
- Authorization Validation: QAR validates the LAR's authority to request revocation
- Registry Update: QAR anchors the revocation event to the TEL registry
- Multi-Signature Coordination: QAR coordinates threshold signatures for the revocation event
Governance-Mandated Revocation
- QVI Termination: If the QVI's credential is revoked by GLEIF, all credentials issued by QARs of that QVI must be revoked
- LEI Lapse: If a Legal Entity's LEI lapses or is retired, all credentials for that entity must be revoked
- Qualification Failure: If a QVI fails Annual vLEI Issuer Qualification, credentials may be revoked
- Grace Period Expiration: Credentials approaching expiration must be revoked if not renewed
Technical Revocation Process
- Revocation Event Creation: QAR creates a revocation event in the TEL
- KEL Anchoring: QAR anchors the revocation event to the QVI's KEL via an interaction event
- Witness Validation: QAR ensures witnesses have validated the revocation event
- Status Propagation: Revocation status propagates through the TEL registry
Primary Governance Frameworks
-
vLEI Ecosystem Governance Framework v3.0
- Establishes overall governance structure for the vLEI ecosystem
- Defines roles, responsibilities, and relationships
- Sets information trust policies and security requirements
-
Qualified vLEI Issuer vLEI Credential Governance Framework
- Defines requirements for QVI credentials
- Establishes QAR qualification and operational procedures
- Specifies credential schema and issuance requirements
-
Legal Entity vLEI Credential Governance Framework
- Defines requirements for Legal Entity credentials
- Establishes LAR verification procedures that QARs must follow
- Specifies multi-signature requirements for Legal Entities
-
Legal Entity Official Organizational Role vLEI Credential Governance Framework
- Defines requirements for OOR credentials
- Establishes identity verification procedures for OOR Persons
- Specifies QAR responsibilities in OOR credential issuance
-
Legal Entity Engagement Context Role vLEI Credential Governance Framework
- Defines requirements for ECR credentials
- Establishes identity verification procedures for ECR Persons
- Specifies QAR responsibilities in ECR credential issuance
-
Qualified vLEI Issuer Authorization vLEI Credential Governance Framework
- Defines requirements for QVI AUTH vLEI Credentials
- Establishes LAR authorization procedures that QARs must validate
- Specifies multi-signature requirements for authorization credentials
Technical Specifications
-
vLEI Ecosystem Governance Framework Technical Requirements Part 1: KERI Infrastructure
- Establishes KERI specification version requirements
- Defines witness pool and backer management requirements
- Specifies key management infrastructure requirements
- Defines cryptographic strength requirements (approximately 128 bits)
-
Trust Assurance Framework
- Maps governance requirements to ISO 20000 certification
- Establishes vLEI Issuer Qualification Program standards
- Defines vLEI software specifications
- Specifies security policies and incident management procedures
-
ACDC (Authentic Chained Data Container) Specification
- Defines credential data structure requirements
- Establishes SAID (Self-Addressing Identifier) protocols
- Specifies graduated disclosure mechanisms
- Defines edge chaining for credential graphs
-
KERI (Key Event Receipt Infrastructure) Specification
- Defines AID creation and management
- Establishes KEL (Key Event Log) structure
- Specifies witness agreement algorithms (KAACE)
- Defines delegation mechanisms
-
IPEX (Issuance and Presentation Exchange) Specification
- Defines credential issuance protocols
- Establishes presentation exchange workflows
- Specifies OOBI exchange procedures
Policy Documents
-
vLEI Issuer Qualification Agreement
- Contractual obligations between GLEIF and QVIs
- Defines QAR qualification requirements
- Establishes performance standards and service levels
- Specifies termination conditions and grace periods
-
vLEI Issuer Qualification Program Checklists
- Annual qualification requirements for QVIs
- Extraordinary qualification procedures
- QAR training and certification requirements
- Compliance verification procedures
-
Information Trust Policies
- Regulatory compliance requirements (GDPR, ISO/IEC 27001)
- Privacy policies for personal data protection
- Data protection standards (Swiss Federal Data Protection Act minimum)
- Security policies meeting industry best practices
Operational Context
QARs utilize specific software tools for credential operations:
-
KERIpy (Python KERI Implementation)
-
KERIA (KERI Agent in the Cloud)
- Cloud-based agent for QAR operations
- REST API for credential issuance and management
- Multi-tenant support for multiple QARs
- Hab (Habitat) management for AID keystores
-
SignifyTS (TypeScript KERI Client)
- Browser-compatible wallet functionality
- Credential presentation and exchange
- IPEX protocol implementation
- OOBI exchange in web contexts
-
Sally (Verification Service)
- Purpose-built for vLEI ecosystem
- Accepts credential presentations
- Integrates with GLEIF Reporting API
- Validates credential chains and status
Multi-Signature Coordination
QARs must coordinate multi-signature operations:
- Group Formation: QARs perform OOBI exchanges to establish the multi-sig group
- Threshold Configuration: QARs configure signing thresholds (typically 2-of-N)
- Event Coordination: QARs coordinate to sign KEL events (inception, rotation, interaction)
- Witness Agreement: QARs ensure witnesses achieve consensus on events
Identity Verification Workflows
QARs follow structured identity verification workflows:
- Video Call Setup: Establish live video session with credential recipient
- Manual Verification: Visually verify legal identity credentials on camera
- OOBI Exchange: Exchange AIDs using QR codes or live chat
- Challenge Generation: Generate unique Challenge Messages
- Signature Verification: Verify cryptographic signatures on challenge responses
- Documentation: Record verification results for audit purposes
Credential Schema Management
QARs must work with specific ACDC schemas:
- QVI Credential Schema:
EBfdlu8R27Fbx-ehrqwImnK-8Cm79sqbAQ4MmvEAYqao
- Legal Entity Credential Schema:
ENPXp1vQzRF6JwIuS-mp2U8Uf1MoADoP_GqQ62VsDZWY
- OOR Authorization Credential Schema:
EKA57bKBKxr_kN7iN5i7lMUxpMG-s19dRcmov1iDxz-E
- ECR Authorization Credential Schema:
EH6ekLjSr8V32WyFbGe1zXjTzFs9PkTYmupJ9H65O14g
- OOR Credential Schema:
EBNaNu-M9P5cgrnfl2Fvymy4E_jvxxyjb70PRtiANlJy
- ECR Credential Schema:
EEy9PkikFcANV1l7EHukCeXqrzT1hNZjGlUk7wuMO5jw
QARs must ensure all issued credentials conform to these schemas and include all required fields.
Conclusion
The QVI Authorized Representative (QAR) role is a critical operational position within the vLEI ecosystem, serving as the human executor of QVI credential issuance authority. QARs bridge the gap between GLEIF's governance requirements and the technical implementation of KERI-based verifiable credentials. Through rigorous identity verification procedures, multi-signature coordination, and adherence to governance frameworks, QARs ensure the integrity and trustworthiness of the vLEI credential ecosystem.