Contextual decisions
One generalized policy engine returns allow, conditions, provisional, deny, defer, escalate or error — with a machine-readable reason code.
OIVN
OWOS Federation
Shared verification infrastructure
OIVN helps OWOS applications verify whether an identity, credential, relationship or access request satisfies the requirements for a specific action. OVIN answers who the actor is. OIVN answers whether the request is valid — and nothing more.
One generalized policy engine returns allow, conditions, provisional, deny, defer, escalate or error — with a machine-readable reason code.
Credential definitions, instances and lifecycle, backed by evidence references rather than copies of anyone else's private data.
OVIN establishes who the human is. OIVN never mints identity and never treats app linkage as authorization.
Every persisted evaluation keeps its policy, reason, missing requirements and evidence references for review.
A clean capability for future Scan / QR / NFC flows to call — OIVN evaluates, the target service still performs the action.
No policy, no passport, or an unavailable dependency all resolve to a denial. Never to an accidental allow.
The boundary
Whether the verification conditions were satisfied, under a named policy, at a point in time.
Who the human is, and whether they consented to one application acting against another.
Whether its own domain rules permit the operation, and then performs it. An OIVN allow is never an execution.