QAEDA-CASE-001 · illustrative scenario

Age assurance without an identity dossier

A service has a legally age-restricted commercial section. It proposes using an independent verifier that returns only a cryptographic over-threshold assertion. The service does not receive a name, birth date, government-ID image, or reusable cross-site identifier, and the assertion expires quickly.

Legitimate objective

What the proposal is trying to accomplish.

Keep minors out of a legally restricted commercial area while preserving adult anonymity and minimizing identity collection.

Proposed mechanism

What actually does the work.

Attribute-level age assurance through a separated verifier, short-lived proof, no account-wide browsing dossier, and a human correction path for false age determinations.

Decisive issue

The safety objective is specific and the mechanism targets eligibility rather than building a general identity-linked record of lawful browsing.

Test-by-test

Do not turn this into a score.

Each finding stands on its own. A serious failure is not canceled by unrelated strengths, and a “clear” result only means the stated facts do not expose that particular defect.

  1. QAEDA-TST-001 Clear on stated facts

    Name the harm precisely

    The protected interest is specific: enforcing an age threshold for a defined restricted service rather than invoking generalized child safety.

  2. QAEDA-TST-002 Clear on stated facts

    Prove the nexus to harmful capability or conduct

    The mechanism tests the eligibility attribute directly instead of inferring age or dangerousness from unrelated behavior.

  3. QAEDA-TST-003 Clear on stated facts

    Test the least-restrictive means

    The scenario uses a narrower attribute proof rather than requiring every visitor to disclose full identity.

  4. QAEDA-TST-004 Clear on stated facts

    Minimize data and separate identity

    Only the threshold result is revealed to the service; identity and inquiry histories remain separated.

  5. QAEDA-TST-005 Clear on stated facts

    Protect lawful inquiry explicitly

    Adults can access lawful material without attaching their civil identity to the content they read.

  6. QAEDA-TST-006 Concern

    Require notice, reasons, and recourse

    Age-estimation and credential errors still need prompt explanation and correction.

    Evidence or change needed

    Publish an error path, response target, and evidence that a human can reverse false denials.

  7. QAEDA-TST-007 Clear on stated facts

    Bound scope, secondary use, and duration

    The proof is short-lived and purpose-limited rather than becoming a reusable general identity token.

  8. QAEDA-TST-008 Concern

    Measure efficacy and make rollback real

    The system still needs measured false-accept and false-reject rates and evidence that it actually improves the targeted safety outcome.

    Evidence or change needed

    Publish aggregate efficacy/error data without retaining individual browsing histories.

  9. QAEDA-TST-009 Concern

    Inspect intermediary chokepoints

    A dominant verifier could become an identity chokepoint even if the proof is privacy-preserving.

    Evidence or change needed

    Support multiple interoperable verifiers and prohibit unrelated secondary use.

  10. QAEDA-TST-010 Clear on stated facts

    Protect the record and independent verification

    Preserve the rules, audits, and aggregate error record—not individualized histories of what people attempted to view.

Revision condition

What would change this assessment?

Move toward redesign if the verifier becomes a persistent cross-site identity broker, if proof tokens become linkable across services, if broad browsing histories are retained, or if error correction is ineffective.

Challenge the assumptions

The scenario facts are part of the argument.

If you can show that a stated assumption is unrealistic, that a narrower mechanism fails in practice, or that a material right or harm is missing, the case should change.