[Openid-specs-risc] openid/sharedsignals: New Issue opened

github at oidf.org github at oidf.org
Tue Aug 4 05:00:36 UTC 2026


openid/sharedsignals event

Issue opened
Issue Title: Subject identifiers don't support instance-level granularity
https://github.com/openid/sharedsignals/issues/346

All WISE subject examples identify a workload at the type level, e.g.: { "format": "uri", "uri": "wimse://trust.example.com/workload/payment-service" } There's no way to identify a specific running instance of that workload. Only the workload as a whole. This matters most for events like workload-compromised and anomalous-behavior-detected. If a fleet has many instances of the same workload running concurrently and only one instance is compromised, a Receiver acting on the event today can only act against the entire workload identity. There's no subject-level way to isolate just the affected instance. Would it make sense to define an instance-scoped subject variant (e.g., an optional instance/run identifier appended to or alongside the workload URI), so events can target a single instance without requiring action against the whole workload?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260804/ced8470c/attachment.htm>


More information about the Openid-specs-risc mailing list