civics.auIdeas for a more resilient society
Australia → the world

10 / Concession credentials

Prove circumstances, not identity.

Concession systems assume a fixed address, a working phone and a willingness to hand sensitive records to every agency and counter. For mobile, displaced or resource-poor people, that design is the barrier. This component proposes attribute-based credentials that travel with the person instead.

Concept notes · Initial draft for discussion
On this pageThe simple ideaWhy concession systems fail mobile peopleAttribute-based credentialsOnline and off-gridAuditable without surveillanceDesigned against misuseWhere it fits the ecosystem

Part of the civics.au concept collection.
Intentions, assumptions & sources ↗

The simple idea

A concession provider may need to know whether someone qualifies. It may not need their full name, address, medical details or personal history to apply the rule fairly.

Diagram showing an eligibility proof issued to a person, checked by a service and used to provide a concession without revealing unnecessary personal history
The proposal is to verify the needed fact while keeping unrelated circumstances private.

Why concession systems fail mobile people

Legacy concession and welfare administration is built for sedentary life. Support schemes routinely require a "principal family home", a fixed postal address, state residency for courses and registrations, or face-to-face appointments—excluding exactly the people who most need relief: survival nomads, people leaving unsafe situations, seasonal workers, and those priced out of housing entirely. Accessing help means repeatedly surrendering the same sensitive records—relationship breakdowns, diagnoses, financial histories—to a chain of agencies and frontline staff, with all the breach and dignity costs that entails.

The same machinery penalises people who contribute public goods without pay—open-source maintainers, community builders, informal carers—who lack the infrastructure (power, connectivity, compute, legal support) that formal systems quietly assume.

Attribute-based credentials

Instead of an identity registry, the design uses W3C Verifiable Credentials and Decentralised Identifiers held in a personal Solid pod. A credential carries attributes of circumstance—an eligibility basis, a residence type (fixed, mobile, none), an income tier, a hardship or transition marker, or a contribution attribute such as uncompensated public-good work or community scaffolding—rather than a dossier of identity documents.

Ontology layerExample attributesWhat it enables
Foundationaleligibility basis, residence type, income tier, family composition, mobility aidsBaseline concession and tariff eligibility without legal name or address.
Hardship & transitionsdomestic-violence marker, safe-exit pathway, disaster impact, destitutionRapid, frictionless assistance without retelling traumatic history at every counter.
Contribution & barriersuncompensated public-good work, community scaffolding, infrastructure poverty, transient residencyReciprocal support—SaaS grants, co-working access, hardware, connectivity—for people whose work underpins the commons.
Programmable grantsgrant balance, merchant category codes, product whitelists, matching ratiosDonor and CSR funds earmarked for specific goods, settled at the point of sale.

Online and off-grid

Online services

A provider (telco, SaaS platform, service program) issues an OIDC4VP request for specific attributes. The holder's pod produces a zero-knowledge proof answering only the boolean question—"eligible or not"—without exposing the underlying reason, identity or history. The provider's rules engine applies the subsidy.

Physical retail, offline

For people without a charged phone—or any phone—a credential is compressed with CBOR-LD into a QR code or NFC card. A POS terminal verifies the issuer's signature locally, checks a product whitelist, debits a prepaid grant balance, and prints a zero-dollar receipt. No connectivity required from the person.

Auditable without surveillance

Funders and tax authorities (ATO, IRS, HMRC) rightly require evidence that concessions and grants reached eligible recipients. The design resolves this with zero-knowledge verification tokens: each transaction appends a compact proof—that a valid, unrevoked credential met the program's rules—to an immutable ledger, without recording who the person was. Auditors verify cryptographic integrity; recipients stay anonymous. Donations routed through deductible-gift-recipient structures, and merchant social tariffs treated as ordinary business debits, both gain a clean evidentiary trail.

Designed against misuse

A concession network aimed at vulnerable people is also a weapon if built carelessly. The architecture is stress-tested against specific failure modes:

  • Digital redlining: verifiers receive only boolean proofs, never raw attributes—an employer or landlord cannot demand "your destitution credential" to filter applicants. Pairwise identifiers prevent cross-merchant correlation.
  • Coercion: safe-exit and deadman-switch protocols let a holder—or a delegated advocate—obfuscate history, revoke an abuser's access and provision a clean-break identity.
  • Fraudulent issuance: only issuers anchored in a governed trust registry can issue high-stakes credentials, blocking Sybil attacks that would drain grant balances.
  • Offline denial of service: carried credentials (QR/NFC) mean the system cannot lock out the very people it exists to serve when devices or networks fail.
  • Algorithmic failure: every automated decision logs its rule ID and circuit version to an auditable record, so appeals and systemic bias can be investigated.

Where it fits the ecosystem

Concession credentials are the entitlement layer for the pricing model described on the Walkabout Strategy page—the $15/night concession floor at community grounds needs a way to verify eligibility without a government-issued card tied to a fixed address. Credentials and receipts are delivered through the Solid databox, and the underlying pods and edge infrastructure are described on the digital economy page. The full analysis—including the STRIDE/LINDDUN threat model and the tax-deductibility treatment—is in the project's social-support ontology working document.

Status: concept architecture, not a deployed scheme. It requires governed trust anchors, issuer accreditation and legal review before any real-world use—and the protections above are requirements, not optional extras.

Continue exploringSolid databox