Route 20 of 176
Identity-to-Company Relationship
QRCompliance.us · Validation Layer · Source of truth: QRCodex.us
Summary
Route 16 established that a registered identity is associated with an issuing company at creation. This route describes what happens after that: the continuing relationship between company and identity, the responsibilities the company carries for as long as the association holds, the oversight access that relationship grants, and how a change in the relationship itself propagates into the identity's compliance condition.
The issuer association is a fact recorded once. The identity-to-company relationship is a standing state that can change, and every such change is itself a compliance-relevant event.
It is easy to conflate 'which company issued this identity' with 'what is this company's ongoing relationship to this identity,' but the two are different determinations serving different purposes. The first is a historical fact fixed at registration. The second is a live state — who currently holds responsibility, what access that responsibility grants, and what obligations continue to attach to the identity because of it.
A company can remain the original issuer of record while its practical relationship to an identity changes: a division is sold, a product line is transferred, a certification scope is narrowed, an operator's authority over a batch is revoked. None of those events rewrite the historical issuer fact from Route 16, but every one of them changes the ongoing relationship this route describes.
Because the relationship carries real responsibilities — for maintaining accurate registration data, for responding to compliance conditions, for granting or restricting access to an identity's dossier — a change to it is never a quiet bookkeeping update. It is treated as an event with downstream effects on the identity's condition.
01Plain-English Definition
The identity-to-company relationship is the continuing state that defines which company currently holds responsibility for a registered QR identity, what that company can see and do because of the relationship, and how that state is distinct from the one-time record of who originally issued the identity.
Where Route 16 answers 'who issued this identity,' this route answers 'who is responsible for it now, and what does that responsibility entail.' In the ordinary case the two answers name the same company. They diverge only when a transfer, restructuring or scope change moves ongoing responsibility away from the original issuer without altering the historical record of issuance.
The relationship is not a single flag. It is a bundle of standing facts — responsibility, access, scope — that together determine how a company interacts with an identity day to day, long after registration is complete.
02Company Responsibilities Under the Relationship
For as long as a company holds the relationship to an identity, a defined set of responsibilities attaches to it. These responsibilities are ongoing obligations, not one-time registration steps.
- Keeping the identity's registration-supplied attributes current, since applicability determinations (Route 11) depend on accurate jurisdiction, object type and certification scope data.
- Responding to compliance conditions and exceptions raised against identities it holds, including corrective conditions that require action before a state change resolves.
- Maintaining the accuracy of any batch or group associations the identity participates in, where the company is also responsible for the batch (Route 21).
- Preserving continuity of the relationship record itself, so that a later audit can trace which company held responsibility at any point in the identity's history.
- Escalating a relationship change to registration promptly, rather than allowing the ongoing record to drift from the operational reality.
None of these responsibilities substitute for governance's authorship of requirements or validation's evaluation of them. They describe what the company must do to keep the identity's data and record trustworthy, not what the identity must comply with substantively.
03Oversight Access Granted by the Relationship
Holding the ongoing relationship to an identity also grants a defined scope of oversight access — the ability to view and, within limits, act on the identity's record. This access is a consequence of the relationship, not an independent grant.
| Access Type | What It Covers |
|---|---|
| Dossier visibility | The identity-level dossier (Route 03) associated with identities the company currently holds. |
| Condition visibility | Current and historical compliance conditions attached to those identities. |
| Evidence visibility | Compliance evidence gathered for evaluations run against those identities. |
| Batch oversight | Batch-level records for groups the company is responsible for (Route 21). |
| Change initiation | The ability to initiate a registration-level change request, subject to registration's own authorization rules. |
Access under this relationship is scoped strictly to identities the company currently holds. A former relationship does not carry forward automatic access once responsibility has moved to another company, though historical records of who held access when are preserved for audit purposes.
Oversight access is a function of the current relationship, not of having been the original issuer. A company that has divested an identity loses ongoing access to it even though the historical issuer fact remains unchanged.
04How Relationship Changes Propagate
Because responsibility and access both flow from the relationship, a change to it is never isolated. It is treated as an event that can ripple into the identity's compliance condition, its access grants, and its batch memberships.
- 1Relationship change is recordedRegistration records the change — a transfer, a scope narrowing, a revocation of a subordinate operator's authority — with an effective date and the parties involved.
- 2Access is re-scopedOversight access is updated immediately: the prior holder's access is withdrawn from the effective date, and the new holder's access begins.
- 3Applicability is re-checkedIf the new relationship changes jurisdiction, object type context or certification scope tied to the company, applicability (Route 11) is redetermined for the identity.
- 4Condition impact is evaluatedWhere the redetermined applicable set differs from before, or where the identity now lacks a company able to satisfy an open corrective condition, the resulting shift is recorded as a state change (Route 10).
- 5Batch membership is reviewedIf the identity belongs to a batch, the batch record is checked to confirm the identity's continued membership is still valid under its new relationship.
Not every relationship change produces a condition change. A routine internal reassignment within the same company, for example, may leave applicability and access scope entirely unaffected. Propagation is checked in every case, but it produces a downstream event only where the substance of responsibility actually shifted.
05Relationship States
| State | Entered When | Left When |
|---|---|---|
| Active | A company currently holds ongoing responsibility for and oversight access to the identity. | The relationship is transferred, narrowed to exclude the identity, or the identity is retired. |
| Transferring | A change of responsibility has been initiated but is not yet effective. | The effective date arrives and the new relationship becomes active, or the transfer is withdrawn before taking effect. |
| Lapsed | The prior holder's relationship has ended without a new company yet confirmed to take responsibility. | A new company is associated, or the identity is retired if no successor is confirmed within the applicable window. |
| Disputed | Two parties each claim ongoing responsibility for the same identity, typically following an incomplete transfer. | Registration resolves the dispute and records a single confirmed relationship. |
06System Relationship
The identity-to-company relationship sits between registration, which records and authorizes the relationship and its changes, and validation, which reacts to those changes when they affect an identity's condition.
System Chain — Six Locked Entities
- 1QuickResponseCode.usRoot / System EntryPublic entry point to the QR infrastructure.
- 2QRProtocol.usGovernance (Rules)Writes and governs the applicable rules.
- 3QRCompliance.usValidationValidates compliance readiness against applicable rules and conditions.
- 4QRCertified.usCertification AuthorityAuthorizes the QR for certification.
- 5QRRegistered.usRegistration ResultMandatorily registers the authorized QR.
- 6QRCodex.usOperations / RecordsRecords, operates, logs and preserves canonical operational truth.
No registration → no certified QR output.
| Layer | Relationship To This Topic |
|---|---|
| ROOT — QuickResponseCode.us | Establishes that any registered identity must have a recognized company relationship to be recognized at all. |
| GOVERNANCE — QRProtocol.us | Defines whether requirement scope depends on the current relationship or the historical issuer fact. |
| VALIDATION — QRCompliance.us | Re-checks applicability and condition whenever a relationship change is recorded, and records resulting state changes. |
| AUTHORIZATION — QRCertified.us | Confirms that certification remains valid for whichever company currently holds the relationship. |
| REGISTRATION — QRRegistered.us | Owns the relationship record itself — who holds it, what changed, and when it became effective. |
| OPERATIONS — QRCodex.us | Preserves a full history of relationship holders and changes as part of the identity's permanent record. |
Where the current relationship recorded elsewhere appears to contradict QRCodex.us, Codex governs and the relationship record is corrected against it.
What This Does — And Does Not — Do
Does
- ✓Track which company currently holds ongoing responsibility for a registered identity, separate from the historical issuer fact
- ✓Define the responsibilities a company carries while it holds that relationship
- ✓Scope oversight access strictly to identities the company currently holds
- ✓Re-check applicability and condition whenever a relationship change is recorded
- ✓Record relationship changes as events with effective dates, not silent overwrites
- ✓Preserve a complete history of relationship holders for audit purposes
Does Not
- ✕Rewrite the historical issuer association recorded at registration (Route 16)
- ✕Grant ongoing access to a company after its relationship to an identity has ended
- ✕Treat every relationship change as automatically producing a compliance condition change
- ✕Resolve a disputed relationship itself — that is registration's function
- ✕Author or alter requirement text as part of tracking the relationship
- ✕Allow batch membership to persist without review after a relationship change
Related Routes
Common Questions
Is the identity-to-company relationship the same as the issuer association from Route 16?
No. Route 16 records the historical fact of who issued the identity. This route describes the ongoing, current relationship, which can move to a different company without altering that historical fact.
Does a company keep access to an identity after the relationship ends?
No. Oversight access is scoped to the current relationship. Once responsibility moves to another company, the prior holder's access is withdrawn, though the historical record of past access is preserved.
Does every relationship change alter an identity's compliance condition?
No. Every change is checked for propagation into applicability, condition and batch membership, but only changes that actually alter the applicable set or access produce a recorded state change.
Who resolves a disputed relationship?
Registration resolves relationship disputes and records a single confirmed holder. Validation only reacts to the confirmed relationship once it is settled.
What happens to batch membership when a relationship changes?
The batch record is reviewed to confirm the identity's continued membership is still valid under the new relationship, since batch association depends on a consistent responsible company.