Sovereign identity is usually presented as an emancipation story. Individuals hold their own credentials, prove only what is necessary, move across services without begging a platform for continued access, and rely less on databases that can be altered, suspended or mined without their consent. That account is attractive, but incomplete. The most revealing test of any identity system is not onboarding. It is succession.
An identity that cannot be revoked by a platform is still fragile if it cannot survive the body that anchors it. Incapacity, dementia, guardianship, disappearance, migration, imprisonment and death are not edge cases. They are predictable events in any population. A system that handles routine authentication elegantly but fails under those conditions has solved convenience, not sovereignty.
By mid-2026, debates about self-sovereign and decentralised credentials are more mature than they were a few years ago. Interoperability frameworks are clearer; the European Union has moved from aspiration to legal architecture through the updated eIDAS framework; and OECD work has made governance, not merely technology, central to digital identity policy. Yet public discussion still tends to underplay a basic political fact: authority over identity is inseparable from authority over transition.
Why inheritance belongs at the centre
In the physical world, identity survives through institutions. Birth registers, passports, court records, wills, powers of attorney and death certificates all provide continuity when a person cannot act personally. They are often slow and imperfect, but they embed a hard-won distinction between ownership, control and representation. A carer may manage an elderly parent’s affairs without becoming that parent. An executor may wind up an estate without acquiring the deceased’s legal personality. A trustee may act under duties that can be reviewed.
Digital systems have often blurred those boundaries. Account recovery mechanisms tend to assume a living, competent user; when that assumption fails, the fallback is customer support, judicial compulsion or unilateral platform policy. That is precisely the model sovereign identity claims to escape. If it is to do better, it must reproduce not the paperwork of analogue bureaucracy, but its jurisprudential insight: continuity requires roles, thresholds and contestability.
Inheritance is where digital architecture collides with family law.
From possession to legal personhood
Many technical designs still lean heavily on possession. If a user controls a device, private key or recovery secret, the system treats that user as the relevant authority. This is practical, but only up to a point. Possession cannot answer whether a spouse should access medical directives during incapacity; whether an adult child may present a parent’s disability credential for care decisions; or whether a research archive may preserve a deceased writer’s attestations while suppressing private attributes.
NIST’s digital identity guidance is useful here because it distinguishes identity proofing, authentication and federation rather than treating them as the same problem. Sovereign identity discussions often collapse those layers into wallet control. But an authenticated signer is not necessarily the legitimate decision-maker, and a legitimate decision-maker may need temporary, scoped authority without permanent transfer of control. The decisive issue is not whether credentials are decentralised, but whether authority can be delegated without becoming unaccountable.
An identity that cannot be revoked by a platform is still fragile if it cannot survive the body that anchors it.
The institutional blind spot in credential design
The credential ecosystem has become good at selective disclosure. It is less good at status transition. A diploma can be attested; a professional licence can be checked; residence can be proved without exposing the underlying number. Those are meaningful advances. Yet the deeper design problem concerns what happens when the subject of the credential cannot exercise agency directly.
Consider three common scenarios. First, a person loses capacity gradually, not suddenly. Decisions about who may act, and for which purposes, may need to tighten over time. Secondly, a refugee or migrant may need to re-establish identity across jurisdictions while family members help manage documents, claims and remittances. Thirdly, after death, some credentials should terminate, some should persist in archival form, and some should become evidentiary artefacts for heirs, insurers or courts. A single revoke-or-retain switch is too crude for all three.
This is where law matters more than code. The United Nations Convention on the Rights of Persons with Disabilities emphasises legal capacity and safeguards against abuse, underscoring that support in decision-making is not equivalent to substitution of the person. In digital terms, that points towards layered delegation, auditable consent histories and purpose-bound authority rather than a simplistic handover of the identity itself.
Europe’s framework is necessary but not sufficient
The revised European digital identity framework is the most significant public effort to create interoperable, legally recognised digital identity rails at continental scale. Its importance lies not only in wallets or trust lists, but in the attempt to align technical standards with liability, assurance and cross-border recognition. That is a serious achievement, especially when compared with the fragmented, contract-led governance that has characterised much of the private web.
Still, even a robust public framework does not settle the succession problem. eIDAS can support trusted assertions and verifiable attributes, but the difficult questions sit at the boundary between identity and civil law. Who appoints a delegate recognised across borders. How is a revocation distinguished from incapacity. What evidentiary weight should a memorialised credential carry after death. Which records must remain portable for the family, and which must become inaccessible to everyone except a court. These are not implementation details. They are constitutional choices disguised as user experience questions.
What a non-revocable identity actually requires
The phrase identity that can never be revoked by a platform is rhetorically powerful, but analytically slippery. No human identity can be beyond all revocation in practice, because many rights and statuses are time-limited, jurisdiction-specific or dependent on external facts. What can be made non-revocable is not every claim, but the person’s ability to remain legible and reconstitutable without any single intermediary acting as sovereign gatekeeper.
That requires at least four properties. First, core identifiers and attestations must be portable across service domains. Secondly, recovery must be plural, so no single actor can extinguish access arbitrarily. Thirdly, delegation must be granular, allowing authority to be lent, constrained and withdrawn. Fourthly, posthumous and incapacity states must be first-class conditions in the system rather than awkward exceptions. Without those features, non-revocability is little more than resistance to account bans.
An identity that cannot be revoked by a platform is still fragile if it cannot survive the body that anchors it.
Inheritance is where digital architecture collides with family law.
The case for fiduciary delegation
A more promising way to think about sovereign identity is through fiduciary structure. In company law, trusts and estate administration, the key question is not merely who holds an instrument, but under what duty and subject to what review. Applied to digital identity, that suggests delegated control should be divisible by purpose and supervised by logs, independent attestations and legal documentation.
A carer might receive authority to present a narrow subset of credentials for healthcare access, but not to transfer property-linked claims. An executor might unlock certificates relevant to probate while being technically unable to read unrelated correspondence. A researcher or archivist might preserve a public-interest record stripped of attributes that serve only curiosity. The system design challenge is to map legal roles into machine-readable permissions without pretending that software can replace adjudication.
That in turn argues against the libertarian fantasy, common in early decentralised identity circles, that all institutional mediation is a defect. Inheritance law, guardianship review and public registries are not bureaucratic clutter around identity. They are part of the mechanism by which societies prevent coercion, fraud and silent dispossession.
Recovery is a governance problem, not merely a security feature
One reason this discussion has lagged is that recovery is often treated as a narrow operational concern. Lose the key, reset the wallet. Yet recovery procedures determine the real sovereign in moments of stress. If a commercial custodian, a telecom operator or a software provider can effectively decide whether a person or family regains access, then practical sovereignty rests there, whatever the rhetoric of decentralisation.
Plural recovery models are therefore essential, but they must be designed with social reality in mind. Family structures are contested. Abuse happens inside households. Not every jurisdiction recognises the same documents. Some users will want state-linked recovery; others will distrust it for good reason. The answer is unlikely to be one universal method. More plausible is a menu of recognised recovery pathways, each with transparent legal effects and evidentiary standards.
UNCITRAL’s work on electronic transferable records is relevant by analogy. It shows that digital control can be made legally meaningful when systems preserve singularity, integrity and reliable control while linking those properties to recognised legal consequences. Identity governance requires a similar move: from technical custody to legally intelligible authority.
Posthumous identity is not the same as data retention
After death, the common policy reflex is to ask what should happen to a person’s data. That is too broad and too vague. The more precise question is which elements of identity should remain actionable, by whom, for how long, and under what duties. A death certificate may need to trigger immediate invalidation of some credentials to prevent fraud. At the same time, educational records, authorship claims, family relationships and memorial instructions may need durable verification for decades.
The decisive issue is not whether credentials are decentralised, but whether authority can be delegated without becoming unaccountable.
Legal scholarship on posthumous privacy has long noted that the dead can still have interests represented through the living, whether because of dignity, reputation, family welfare or testamentary intent. Digital identity systems should not assume that death collapses all claims into either public archive or total deletion. The right model is differentiated persistence: some assertions expire, some become evidence, some pass under fiduciary control, and some remain sealed absent judicial process.
The geopolitics of continuity
There is also a sovereign question in the classical sense. If a person’s enduring identity depends on a foreign cloud provider, a foreign standards body, or a contractual chain beyond domestic review, then national capacity is thinner than it appears. This does not imply digital autarky. It does imply that states and regional blocs need continuity mechanisms they can audit and contest when markets fail, firms disappear or jurisdictions diverge.
The BIS has stressed that trust is foundational to digital identity. Trust, however, is often misdescribed as mere user confidence. At state scale it means institutional reliability under adverse conditions: bankruptcy, cyber attack, conflict, sanctions, family dispute, or the death of the credential holder. A sovereign identity infrastructure that works only in peacetime and only for healthy adults is a fair-weather system.
Design principles for the next phase
If sovereign identity is to mature, several principles follow. Identity wallets and credential stores should support pre-authorised delegation roles with clear scopes and expiry conditions. Revocation registries should be able to express reason and context, distinguishing fraud from death, incapacity and administrative correction. Audit trails should be legible to courts and regulators rather than only to engineers. Cross-border recognition schemes should include standard ways to evidence guardianship, executorship and supported decision-making.
None of this abolishes the need for institutions. It redistributes dependence. The aim is not to eliminate trusted third parties, which is neither feasible nor always desirable, but to prevent any one of them from having unilateral power over a person’s civil legibility. In practical terms, that means identity systems should be designed to fail into reviewable procedure, not into silence.
The real measure of sovereignty
There is a tendency in technology policy to assess identity systems by adoption numbers, fraud reduction or transaction speed. Those metrics matter, but they are not the final measure. The real test is whether a person remains recognisable in law and society when ordinary agency breaks down. Children become adults. Adults become dependent. Families dispute. Estates are wound up. Borders are crossed. Institutions merge or vanish.
Sovereign identity will deserve the adjective only when it can navigate those transitions without reducing the individual to a recoverable account. That is a more demanding ambition than passwordless login or portable credentials. It forces designers, lawmakers and courts to confront identity not as a static profile but as a civic continuity problem.
The frontier, then, is not simply decentralisation. It is succession with safeguards. Systems that can prove who you are while you are healthy and online are useful. Systems that can preserve your agency, delimit others’ authority, and carry your legitimate claims through incapacity and death are politically serious. By that standard, the field’s most important work is still ahead of it.



