Decentralized Trust Graph Working Group

Decentralized Trust Graph Working Group

Introduction

The purpose of the Decentralized Trust Graph Working Group (DTGWG) is to define the standards for building decentralized trust graphs—portable graphs of trust relationships between people, groups, organizations, AI bots, and so on—using standard features of the ToIP stack such as verifiable identifiers (such as W3C Decentralized Identifiers (DIDs) 1.0), and verifiable digital credentials (such as W3C Verifiable Credentials Data Model 2.0).

Scope

Following is the official statement of the working group scope from the DTGWG charter:

The scope of the Decentralized Trust Graph Working Group (DTGWG) is to define the socio-technical standards for a decentralized trust graph where there is no centralized database and all parties control their own subgraph of trust relationships. This work includes specifying requirements for key management and recovery, verifiable identifiers, verifiable credentials, verifiable relationship credentials, social vouching, relationship cards (r-cards), privacy-preserving zero-knowledge proofs, trust task protocols, trust registries, out-of-band introductions, UI/UX affordances, decentralized naming and discovery mechanisms, and governance considerations. This work will be based on the Design Principles for the ToIP Stack, the ToIP Technology Architecture Specification, other ToIP technical specifications, and complementary open standards for decentralized digital trust infrastructure.

Leadership

Please add your name here if you wish to be a candidate to co-chair this WG:

  • @Drummond Reed (First Person Project)

  • <add your name here>

Membership

Please add your @ name here if you wish to be a member of this WG:

  • @sankarshan

  • @Markus Sabadello

  • @John Phillips

  • @Vikas Malhotra

  • @Adam Larter

  • @Martina Kolpondinos

  • @Jorge Flores

  • @Scott Perry

  • @Rob Aaron

  • @Nicky Hickman

  • @Daniel Glinz

  • @Mitchell T

  • @Jo Spencer

  • @Joaquin Salvachua

  • @Steven Milstein

Task Forces

It is expected that much of the work on deliverables of the DTGWG will be performed by self-organizing Task Forces (TFs). Following are the proposed initial set of TFs (each TF name with a link has published a TF home page):

  1. Risk Assessment and Harms Prevention Task Force—Analyses the overall requirements and potential harms for a successful decentralized trust graph, produces a risk assessment analysis and a recommendation on policies and best practices to prevent harms.

  2. Credentials Task Force—Define the technical requirements for personhood credentials (PHCs) and verifiable relationship credential (VRCs), including credential formats, signature algorithms, zero-knowledge proofs, and revocation mechanisms.

  3. R-Cards Task Force—Define the technical requirements for relationship card (r-card) interoperability and extensibility.

  4. Trust Task Protocols Task Force—Define trust task protocols for standard DTG trust tasks, including QR codes, pairwise private DID exchange, PHC/VRC issuance and verification, r-card exchange, and personal private channels.

  5. UX Task Force—Define UX requirements and guidelines for sovereign wallets and standard user ceremonies for each of the primary trust tasks above.

  6. Peer-to-Peer PHC Task Force—Define the technical and governance requirements for issuing PHCs that do not require centralized PHC authorities yet can still be verified as authentic.

Deliverables

The DTGWG will develop a list of target deliverables as an early work item.

Name

Type

Task Force

Content Notes (Preliminary)

Anticipated Time Frame

Name

Type

Task Force

Content Notes (Preliminary)

Anticipated Time Frame

DTG Risk Assessment Matrix V1.0

Recommendation

Risk Assessment & Harms Prevention TF

Risk Assessment Matrix based on the ToIP Risk Assessment Companion Guide and Template

Public Review Draft, January 2026

DTG Human Harms Prevention Business Requirements Definition V1.0

Recommendation

Risk Assessment & Harms Prevention TF

  • A set of business requirements against the human roles and their lifecycle.

  • Recommended governance requirements for the identification, prevention, detection of, the response to, and recovery from human harms associated with use of DTG

  • Comparison with use of biometrics

Public Review Draft, January 2026

DTG Credentials Specification V1.0

Spec

Credentials TF

Personhood Credential (PHC) Schema
Verifiable Relationship Credential (VRC) Schema
Extensibility
ZKP Proofs
VID/DID Requirements (includes privacy-preserving persona requirements)
UX Requirements
Security, Privacy, Accessibility, Sovereignty Considerations

Public Review Draft for Linux Foundation Member Summit, 23-25 February 2026

DTG Credentials Exchange Protocols Specification V1.0

Spec

Credentials TF

PHC Issuance Protocol
VRC Issuance Protocol
VRC Notarization Protocol
ZKP Presentation Protocol
Out-of-Band Introduction Protocols
QR Codes
UX Requirements
Security, Privacy, Accessibility, Sovereignty Considerations

Public Review Draft, June 2026

R-Cards Schema and Protocol Specification V1.0

Spec

R-Cards TF

R-Card Schema
Extensibility
Exchange Protocol
UX Requirements
Security, Privacy, Accessibility, Sovereignty Considerations

Public Review Draft, June 2026

DTG Sovereign Wallet Guide

Recommendation

Credentials TF + R-Cards TF

Best Practices Guide

Public Review Draft, October 2026

Meetings

Beginning 08 October 2025, the DTGWG will hold weekly meetings in two editions to accommodate global time zones:

  • The AM/EU meeting will be Wednesdays from 08:00-09:00 PT / 15:00-16:00 UTC.

  • The APAC meeting will be Wednesday 18:00-19:00 PT / Thursdays Sept 25 01:00-02:00 UTC

See the ToIP Calendar for all meeting dates, times and logistics, including Zoom links.

We will produce one consolidated set of meeting notes for both editions together. (Where it is helpful, the notes will indicate which notes were taken in which meeting.)

See the DTGWG Meeting Page for an index of all Meeting Pages with agendas, notes and recordings from all meetings.

Discord Channel

ToIP uses a set of channels under the “ToIP” category on the LFDT Discord. Our WG channel is:

#toip-decen-trust-graph-wg

To join:

  • Go to Join the Linux Foundation Decentralized Trust Discord Server.

  • Accept the invite.

  • Since the LFDT Discord serves all LFDT projects, you will see channels grouped by category.

  • If you only want to follow ToIP channels, search "ToIP" in Browse channels, then select "Follow Category”. You can also select specific channels under the ToIP category so these channels will appear in your left navigation panel.

Participation

For the protection of all Members, participation in working groups, meetings and events is limited to members, including their employees, of Trust Over IP (ToIP) or Decentralized Identity Foundation (DIF) who have signed the membership documents and thus agreed to the intellectual property rules governing participation. If you or your employer are not a member of ToIP or DIF, you may not participate in meetings by verbal contribution or otherwise take any action beyond observing. 

How to join

  • To join ToIP, please fill out the membership application here

  • To join DIF, please fill out the membership application here.

After you have joined Trust Over IP, you can join this WG by signing up for the Working Group's mailing list. Use this link [LINK TO BE ADDED] to signify your acceptance of the WG charter and desire to participate in the DTGWG. Scroll to the bottom of the page.  Log-in using your group.io username and password or LF ID. Then click on the blue button [+Join This Group].

Members as well as observers are welcome (with the important caveat below).

Intellectual Property Rights (Copyright, Patent, Source Code)

The following IPR terms are specified in the JDF Charter: