TamgaNetwork

Concepts

What is digital identity?

Identity is the verifiable representation of “who” an entity is. Digital identity is its counterpart in the digital world.

First, what is “identity”?

In everyday life, by identity we usually mean an ID card. But identity is actually broader than a card: it is what makes you you, distinguishes you from others and shows continuity over time. Your name can change, your address can change; but “you” remain the same person.

Key distinction: identity ≠ document

Identity is continuous. Documents (ID card, diploma, driving licence) are proofs bound to that identity that change over time. In Tamga this distinction is fundamental: identity stays fixed, while the documents attached to it come and go.

What does a digital identity represent?

Digital identity is not only for people. Every entity on the network can be represented by an identity:

  • Person Identity — represents an individual. A single lifelong identity; all documents and relationships attach to it.
  • Organization Identity — represents a legal entity: a university, hospital, company or public institution.
  • Asset Identity — represents a physical or digital asset: a vehicle, container, device or sensor.
  • Agent Identity (future) — autonomous AI agents acting on behalf of an organization.

Identity vs. role

Identity says “who you are,” a role says “what you can do.” A university can be both an Issuer (it issues diplomas) and a Verifier (it verifies other documents). Identity stays fixed; roles change with context.

This distinction yields an important principle: the source of authority is always an organization. A physician writes a prescription not in their own name, but with the verifiable authority granted by the institution they work for.

Self-sovereign identity (SSI)

Self-Sovereign Identity (SSI) is the approach where control of identity belongs not to a central institution but to the user themselves. You carry your own documents; you decide what to share with whom. Tamga Network embraces this principle; in the following pages we’ll see the technologies that make it possible (X.509, verifiable credentials, selective disclosure) one by one.