Human Resources G2C Use Case
MyID Consent PoC Walkthrough
A step-by-step demonstration of consent and ID proof-based digital identity in action. Presenting how ID Exchange's MyID Consent service is deployable in a Enterprise or Government application.
Overview
This proof of concept demonstrates how a consent-first digital identity system could operate in a Human Capital onboarding services context for Government. The walkthrough covers five key stages — from identity setup through to verified data sharing and audit trail review.
MyID Consent connects verified candidate identity and granular consent directly into the nominated Department recruitment process, integrating securely with the Recruitment systems of choice via encrypted, standards-based APIs — so candidates share only what each screening step requires, with a full audit trail.
Click through every screen of the HR Onboarding & IP Proof journey in a mobile-app preview.
Identity Setup & Credential Issuance
The PoC is structured for an Australian Government employment candidate who is sent an invitation for their specific job offer and to commence the process via myID Consent link. This link lands at the appropriate Government branded MyID Consent overview page with instructions to download the app or access the webservice.
- User downloads or accesses an identity wallet application
- Identity documents are verified by an accredited issuer
- W3C-compliant Verifiable Credentials are issued to the wallet
- Credentials are cryptographically signed and tamper-evident
Consent Request Initiated
A API screening/vetting party — such as for Security screening, Police check, Right to Work or HR systems — requests access to specific identity attributes. The user receives a clear, plain-language consent request related to the specific job pack or where they have opted in for other shared services use.
- HR system sends a structured consent request based on Job role and Screening requirement.
- Request specifies exactly which attributes are needed
- User sees a plain-language summary before deciding
- User can accept, decline, or partially approve the request
Selective Disclosure & Data Sharing
Upon consent, only the approved attributes are shared — nothing more. Zero-knowledge proof techniques can verify claims without revealing underlying data.
- Only consented attributes are released to the relying party
- Zero-knowledge proofs enable verification without full disclosure
- Data is shared via encrypted, standards-based protocols
- No centralised data store — data remains with the user
Verification & Trust Confirmation
The relying party verifies the credential's authenticity against the issuer's public key — without contacting the issuer directly. Trust is established cryptographically.
- Credential signature is verified against issuer's DID
- Revocation status is checked in real time
- No issuer contact required — fully decentralised verification
- Result: verified identity attribute with full audit trail
Audit Trail & Consent Withdrawal
Every consent event is logged in an immutable audit trail. The user retains the right to withdraw consent at any time, immediately revoking the relying party's access.
- Full audit log of all consent events is maintained
- User can review who has accessed their data and when
- Consent can be withdrawn instantly via the wallet
- Withdrawal triggers immediate access revocation
Technical Architecture
The PoC is built on open, interoperable standards — ensuring no vendor lock-in and full alignment with international best practice. These building blocks are backed by conformance-tested, open-source implementations such as Affinidi's Verifiable Trust Infrastructure, so the architecture stays transparent and verifiable rather than proprietary.
Decentralised Identifiers (DIDs)
W3C DID standard enables self-sovereign identity — users control their own identifiers without relying on any central authority.
Verifiable Credentials
W3C VC standard enables tamper-evident, cryptographically signed credentials that can be verified by any party without contacting the issuer — supporting multiple formats including SD-JWT VC and ISO/IEC 18013-5 mobile documents (mDoc).
Solid Pods
Personal Online Datastores (Pods) give users a secure, private data store they control — granting and revoking access on their own terms.
Zero-Knowledge Proofs
Prove a claim is true — such as "over 18" or "Australian resident" — without revealing the underlying personal data.
Trust Registries & Verifiable Trust Infrastructure
Open Verifiable Trust Infrastructure (VTI) and Trust
Registries let a relying party confirm an issuer is
accredited — establishing who can be trusted before a
credential is ever accepted, using portable
did:webvh identifiers.
Standards-Based Secure Messaging
Consent requests and credential presentations travel over sender-authenticated, encrypted channels — DIDComm v2 and the Trust Spanning Protocol — so exchanges stay private and replay-safe across organisational boundaries.
Regulatory Alignment
This PoC is designed with Australian regulatory requirements at its core — not as an afterthought.
🏛️ Digital Identity Act 2024
Consent-first design, accredited issuer framework, and interoperability requirements are all addressed within this PoC architecture.
📊 Consumer Data Right (CDR)
Selective disclosure and granular consent management align directly with CDR's data minimisation and purpose limitation principles.
🔒 Privacy Act 1988
Immutable audit trails, consent withdrawal rights, and data minimisation support compliance with Australian Privacy Principles.
🌐 GDPR Alignment
For organisations operating across jurisdictions, the architecture supports GDPR's right to erasure and data portability requirements.
Explore the Vendor Solutions
See how Affinidi and Inrupt each approach the technical challenges outlined in this walkthrough.