top of page

Who Should Operate Trusted Digital Services in DPI?

  • Writer: Ott Sarv
    Ott Sarv
  • Apr 5
  • 5 min read

Updated: May 25

Public-sector governance team reviewing digital trust architecture, showing that trusted digital services in DPI remain public when authority, mandate, evidence, oversight and remedy stay attributable across the governance chain.
Operator form is not the source of legitimacy. Trusted digital services remain public when lawful authority, institutional mandate, evidence pathways and procedural remedy remain operable across the governance chain.

Trusted digital services do not need a single public operator to remain public. What matters is whether lawful authority, institutional mandate, evidence, oversight, and remedy remain attributable and operable across the full governance chain of Digital Public Infrastructure.

Why operator ownership is the wrong starting point

The usual argument begins with ownership. It asks whether trusted digital services should be run directly by the state or by some other operator, as if ownership of the channel were the real test of legitimacy. That is too narrow for Digital Public Infrastructure. Once a digital system produces legal effect, the decisive issue is not who hosts the machinery. The decisive issue is whether public authority remains lawful, attributable, reviewable, and correctable when execution becomes digital, modular, and widely relied upon.

That is why the better starting point is legal sequence, not platform centrality. The Seven Layer Model treats Digital Public Infrastructure as a medium through which public authority is exercised and legal effect is produced at scale. It makes lawful authority, institutional mandate, an evidence pathway sufficient for review, and procedural remedy the threshold conditions of legitimacy.

The governance chain behind trusted digital services

The Seven Layer governance architecture is not a software stack. It is a sequence of governance questions that must remain distinct from one another. The chain runs from Layer One: Legal authority through Layer Two: Institutional mandate, Layer Three: Canonical records, Layer Four: Service logic, Layer Five: Execution layer, Layer Six: Public interface, and Layer Seven: Oversight and remedy. The paper is explicit that later stages may implement earlier ones, but may not redefine them.

This matters because legitimacy is not created by delivery performance alone. The paper distinguishes clearly between operational success and governance legitimacy. A system may be efficient, scalable, and widely used while lacking a defensible legal and institutional basis. That is also why digital sovereignty depends on sequence rather than on software assembly alone. If authority, mandate, records, logic, execution, interface conditions, or remedy are displaced downstream, the system may still function, but the governance chain has already started to weaken.

Operational centrality does not confer governance authority.

What operator form changes and what it cannot change

Operator form matters, but it does not govern alone. A directly public model, a model under mandate, and a model based on public recognition do not create the same control conditions. They change how supervision, qualification, liability, evidence access, and correction reach must be organised. But they do not replace the governance chain itself.

This is the point that gets lost when digital trust is reduced to an ownership choice. A technically central component may support execution. A shared capability may support verification. A channel may support disclosure or routing. Yet neither technical centrality nor routing centrality becomes the legal source of the act. That is why institutional authority and data exchange governance matter here. The issue is not whether a component is useful. The issue is whether authority, responsibility, and remedy remain where the law expects them to remain.

The Seven Layer paper sharpens this further. It states that every programme requires full seven-layer assessment, even where a layer is directly constituted, shared, inherited, partially engaged, or not activated. That means operator form has implications across all seven layers, but it should not be mistaken for a substitute for them. Public responsibility remains anchored in the full governance architecture, regardless of how execution is arranged.

Why a single trusted channel still feels attractive

The persistence of the single-operator instinct is not irrational. It has institutional roots. The older postal model kept alive the idea that one trusted channel could combine protected communication, receipting, and evidentiary handling in one recognisable public form. The electronic postal registered mail strand of the UPU framework still reflects that logic in digital form.

That legacy remains useful, but only within limits. It explains why governments still value continuity, proof, and a trusted public-facing channel. It does not prove that one operator should absorb the whole trust architecture. The Seven Layer paper is clear that registries, trust services, orchestration platforms, and public interaction channels may all appear central in practice, yet none acquires governance authority through operational centrality alone.

What the European framework shows about operator models

The current European Digital Identity Wallet framework is useful because it makes the separation between public responsibility and operator form more visible. The governing framework sits at Union level, while the operational route is not collapsed into a single ownership model. In the same legal family, the rules on trust service providers and the regime of trusted lists show that legal effect depends on public supervision, recognised status, and qualification, not on ownership alone.

That does not make operator choice trivial. It makes the legal test more demanding than a public-versus-private binary. The correct question is whether authority remains attributable, whether the accountable institution remains identifiable, whether records remain authoritative, whether service logic remains governed, whether execution remains reconstructable, and whether remedy can still intervene in time and with legal effect. The paper treats these conditions cumulatively. One does not compensate for the absence of another.

The governance test before reliance expands

This leads to a stricter rule for governments. Before reliance expands, they should ask whether the function itself is lawfully constituted, whether a named institution remains accountable for it, whether canonical records remain governed, whether service logic still reflects authorised procedure, whether execution remains attributable, and whether oversight and remedy can still reach the operative outcome. The Seven Layer paper makes clear that reliance must not outrun governance, and that delivery readiness cannot cure a governance object that was never lawfully constituted in the first place.

This is also where governance drift begins. It begins when configuration starts to shape legal meaning, when shared capabilities are treated as if they were decision-makers, when evidence fragments across programmes, or when remedy remains formally present but becomes practically unreachable. The paper treats that not as an incidental defect, but as a recurring structural condition in digital public infrastructure.

Remedy cannot be assumed from interface design.

So who should operate trusted digital services in DPI?

The better answer is that operator form must remain subordinate to governance architecture. Some functions may be operated directly by public institutions. Others may be operated under mandate. Others may sit inside a recognised and supervised framework. But none of those arrangements is legitimate merely because the operator is central, efficient, or technically trusted.

It is not decisive who delivers the capability. What is decisive is whether lawful authority, institutional mandate, a reconstructable evidence pathway, and procedural remedy remain attributable and operable across the full governance chain. Delivery form may vary, but public authority cannot be displaced. That is why digital trust is not a monopoly question. It is a governance question.

Meet the author of the Seven Layer Model for Digital Public Infrastructure

Ott Sarv

  • LinkedIn
Ott Sarv The Seven Layer Model Author

author of the Seven Layer Model for Digital Public Infrastructure

Senior advisor in Digital Identity and Digital Public Infrastructure. Ott Sarv helps institutions align lawful authority, institutional mandate, canonical records, and machine-readable rules with verifiable execution, enabling enforceable outcomes. Engagements combine policy, architecture, and delivery support.

Download the Seven Layer Model for DPI

This paper is shared with practitioners and researchers working on digital public infrastructure and digital identity.


Submit your details to receive the PDF access link.

bottom of page