Manav.id
Definitional · 5 min read

The consumer identity budget: what a person can reasonably be asked to do

The consumer identity budget: what a person can reasonably be asked to do

This article argues against a large part of the rest of this series, and it is published at the same tier as the pieces it complicates. If a control's coverage model shows meaningful exclusion and there is no funded assisted path, the honest answer is that it should not ship.

How much identity work can you reasonably ask a person to do?

Far less than the sum of what every sector is currently proposing. Banking, gambling, telecoms, healthcare, government and marketplaces are each designing per-action authorisation simultaneously. The strongest argument against the whole portfolio is not technical but distributive.

Key takeaways
  • Authorisation controls are designed against a median user with a modern phone, reliable connectivity and no accessibility needs. In benefits, healthcare and elder finance, the edge is the population.
  • Coverage must be measured against the specific population, not general statistics, and the gap between the two is consistently large.
  • An exclusion budget, set before design and measured after deployment, is the only mechanism that makes the tradeoff reviewable.

Why this is published at all

Bank: sign every large transferreasonableTelecom: sign SIM changesreasonableGambling: sign withdrawalsreasonableGovernment, health, marketplaces…each reasonableOne person, all of itunreasonable
Each proposal is defensible alone. Nobody is adding them up.

The preceding records in this series propose asking consumers to sign for consequential actions across benefits, healthcare, gambling, settlements, marketplaces and financial services. Each argues that the control is narrow and the value is high.

Every one of them is weakened by the same objection, and the objection is correct: a control that works for most people and fails for some has redistributed harm rather than eliminating it, and the people it fails are systematically the ones with least capacity to absorb it.

A portfolio that did not include this piece would be commercially cleaner and intellectually dishonest.

The measurement error at the centre of this

Product teams size coverage using general population statistics: smartphone penetration, broadband access, app store reach. Those numbers are high in most markets and they are the wrong numbers.

The relevant population is the one using the specific service, and for the services where per-action authorisation matters most, that population is systematically different from the general one.

The gap is consistently in the same direction. Measure the right column; never substitute the left.
ServiceGeneral population assumptionActual user population
Public benefitsSmartphone ~90%+Unstable housing, shared devices, prepaid plans with data limits
Elder financial servicesSimilar to generalMedian age 70+, assisted use, cognitive variation
Settlement administrationSimilar to generalIncludes elderly, unbanked, institutionalised claimants
Disaster assistanceSimilar to generalDisplaced, devices lost, no connectivity
Clinical patient portalsSimilar to generalIllness, disability, caregiver-mediated access

The coverage model

Before designing a control, produce this for the actual population.

  1. Device access. Share with a personal device capable of holding a credential. Not household access — personal.
  2. Device exclusivity. Share whose device is not shared with a household member. This matters where coercion is a risk.
  3. Connectivity. Share with connectivity sufficient at the moment of the action, not on average.
  4. Accessibility. Share for whom the interaction is usable with their assistive technology.
  5. Assistance. Share who can complete it with available help, where they cannot alone.

Multiply through and the result is the reach of your primary mechanism. The remainder is the population your assisted path must serve, and its size determines whether that path can be a queue or must be a staffed service.

The exclusion budget

State, before design, the maximum share of the eligible population that a control may exclude or materially delay.

Then do the arithmetic in people rather than percentages, because percentages hide the number that matters. A control reaching 96% of a two million person caseload leaves 80,000 people. If the assisted path has a six-week backlog, the control has denied 80,000 entitled people timely access to money they need.

An unstated exclusion rate is still an exclusion rate. Stating it is what makes the decision reviewable by someone other than the team that made it.

The exception path is an attack surface

A point that cuts against the naive design and is frequently missed. Whatever assisted path exists for people who cannot use the primary mechanism becomes the path an attacker selects.

That is not an argument against having one — not having one is worse. It is an argument that the exception path needs its own controls, its own monitoring, and its own rate limits, and that a control whose exception path is unguarded has moved the vulnerability rather than closing it.

What this implies for the rest of the portfolio

Applied honestly, several of the consumer-facing proposals in this series should be sequenced behind work that does not currently have funding.

Those are constraints on our own arguments, and they are stated here so that a reader implementing any of them does so with the constraint visible rather than discovered.

The thing the industry does not publish

Identity vendors publish adoption rates, enrolment velocity, fraud reduction and conversion improvement. No vendor publishes the share of a population its control could not reach.

That number exists in every deployment. Asking for it is a reasonable procurement question, and the response to it tells a buyer more than any case study.

Who runs out of budget first

The people for whom this compounds worst
GroupWhy
Device-limited householdsOne shared phone across several people's obligations
Older adultsMore institutions, less tolerance for new mechanics
Carers and proxiesActing for someone else across every sector at once
The thinly documentedAlready the hardest to enrol anywhere

This is an argument the industry publishes adoption rates about and rarely publishes exclusion rates about. A control at 97% adoption sounds excellent and means three people in a hundred cannot complete the action.

Objections and honest limits

“One credential works everywhere.” It can, technically. The barrier is that each sector wants its own enrolment, its own recovery and its own assurance level, so the person enrols repeatedly.

“The alternative is more fraud.” Partly, and that trade should be made explicitly per action rather than absorbed silently by whoever cannot complete the step. Publishing exclusion rates alongside adoption is the minimum.

Spending the budget well

  1. Gate the rarest, highest-consequence actions only. Frequency is what determines the real cost to a person.
  2. Re-use one enrolment across your own actions. Do not make a person enrol per product line.
  3. Support more than one credential type. Phone, hardware key, and a staffed in-person path.
  4. Publish exclusion alongside adoption. A control nobody measures the cost of is a control nobody can defend.

Terms used here

Identity budget
The total authentication effort a person can absorb across every institution before some of them become unusable.
Exclusion rate
The proportion of legitimate users who cannot complete a control — systematically under-measured because they leave.
Proxy access
Acting on another person's behalf, which multiplies the budget problem across every sector at once.

Frequently asked questions

Does this argue against per-action authorization? It argues that coverage must be measured and an exclusion budget set before deployment, and that several proposals in this series should be sequenced behind assisted-path funding.

Is the exception path not a hole in the control? Yes, and the alternative — no exception path — excludes people who are entitled. The correct response is to control and monitor the exception path, not to remove it.

Why publish this alongside the proposals it complicates? Because the objection is correct and a portfolio that omitted it would be marketing. It is also publishable by a competitor as-is, which is the test of whether it is honest.

What should a buyer ask a vendor? What share of our specific population could not complete enrolment, measured rather than estimated, and what does your assisted path cost to staff at our volume.

Is this an argument against per-action authorisation? It is an argument against deploying it everywhere at once without anyone counting the total. The control is right for rare, high-consequence actions.

Who bears the cost first? Device-limited households, older adults, carers acting for others, and the thinly documented.

What should operators publish? Exclusion rates alongside adoption rates. A control whose cost nobody measures is one nobody can defend.

Where this fits in Manav

Manav proves a specific person authorised a specific action, without a vault, a token or surveillance. The biometric never leaves the device and the platform receives a signature rather than a profile.

What we do not do →

Sources and further reading