From Identity to Federation

Following one resource across independently governed Semantic Spaces

A concept in the RSM space, a research paper in Wellzai, and a fieldnote in Musewoods reference each other without sharing a database. This Journal follows that chain through citation, exploration, transfer, and restriction to show how persistent references, provenance, and authority let federation work.

RSM ID Learning Center8 min read

Federation is often imagined as a merger in slow motion: separate systems agree on a schema, copy their records into a shared store, and eventually become one. RSM ID proposes something different. Independently governed Semantic Spaces keep their own databases, software, policies, and editorial lifecycles, and they cooperate by agreeing on one thing only — which resource each reference is about. The thesis of this Journal is that a persistent identifier, carried with provenance and checked against registered authority, is enough to let knowledge connect across organizations without anyone surrendering control of it.

To make that concrete, we will follow one small chain of resources that Documents 08 and 09 use as their own example, across the three Semantic Spaces proposed for the initial federation: RSM, Wellzai, and Musewoods. The identifiers are the specifications' illustrative examples and this site's demonstration records; none has been issued, and none of the spaces is deployed.

Three spaces, three resources

The RSM Semantic Space maintains the foundational concept of Formation. In the demonstration it has the RID 451.5VJC3VFV46EVR73V and the registered name rrn:451:451labs:global:rsm:concept/formation. The Wellzai space maintains a research paper, the Outcome Formation Model, with the specification's example RID 451.7K4M9Q2X8D5P0R6T. The Musewoods space maintains a fieldnote, Code Meets Soil, with the demonstration RID 451.5Z7MCTTCHRBCBS2S and the name rrn:451:451labs:us-ca:musewoods:document/code-meets-soil. Each space has its own RID and RSN, because each space is itself a governed resource.

The paper does two things that make it interesting. It extends the RSM concept of Formation, and it cites the Musewoods fieldnote. Neither of those resources belongs to Wellzai, and Wellzai has no reason to copy them. In a world of application-bound identifiers, the paper would store a URL for each — a path into another organization's website — and the links would break the next time either site was redesigned.

Figure 1

Rendering diagram…

In RSM ID, the paper's connection to Formation is recorded as a relationship that names both ends by RID. That sounds like a link with a better address, but the specification asks for more. The relationship keeps the space in which it was asserted (Wellzai), the predicate (extends), the authority that made the assertion, and its provenance. That extra information is what lets a reader in another space decide how much weight to give it. Wellzai can say that its paper extends Formation; it cannot thereby change what Formation means, because the authoritative definition stays in the RSM space.

This is the practical meaning of provenance in a federation. Every claim travels with the answer to who said this, under what authority, and when? A relationship that needs its own lifecycle, permissions, or revision history can even receive its own RID, which is why relationship is one of the twelve kinds in the minimum kind profile. Most relationships do not need that, but the possibility shows how seriously the architecture treats assertions as things with identity and history of their own.

Traversing the chain with Atlas

Now imagine a reader exploring the federation through Atlas, the proposed explorer of federated Semantic Spaces. They find the paper through Wellzai and follow its relationship to Formation. Atlas does not look for a page titled Formation and hope it is the right one; it resolves the RID 451.5VJC3VFV46EVR73V, the resolver verifies the 451 prefix and the binding to the RSM space, and the RSM space returns its permitted representation. Document 08's worked example describes exactly this: Atlas discovers the paper through Wellzai and traverses into the RSM space without copying the authoritative concepts into Wellzai (§13.2).

Figure 2

Rendering diagram…

Aggregation is allowed; appropriation is not. Atlas may combine search results from all three spaces and use the RID as the deduplication key, so the same paper found through two routes appears once. What it may not do is present its combined view as canonical knowledge of its own. A cached copy of the RSM definition inside Atlas is a projection with a retrieval time and a source, not a second authority.

Version 1.1 tightens this further on the wire. A server may not describe a cached projection as authoritative without a verified provenance chain, and resolvers must verify prefix authority, issuer provenance, lifecycle, and an active authoritative-space binding before relying on a remote representation (§18.6, §18.8). A remote system's claim to be authoritative is not evidence that it is.

When a resource changes spaces

Suppose the Outcome Formation Model matures into a foundational reference and responsibility for it moves from Wellzai to the RSM space. Document 08 uses this very case. The paper keeps 451.7K4M9Q2X8D5P0R6T. A successor name, rrn:451:451labs:us-ca:rsm:document/outcome-formation-model, may be registered through an authenticated transfer, while the original Wellzai name stays reserved and continues to resolve to the same RID. Every relationship that referred to the paper — including the Musewoods fieldnote's backlinks and any citation in the wider world — keeps working without an edit.

Document 09 is candid about what makes this hard. The registry and the two Locus nodes cannot be updated in one atomic transaction, so a transfer needs explicit handling for a target that fails after cutover, stale resolver caches, and split-brain situations. What the architecture guarantees is narrower and more valuable: whatever happens to the bindings, the canonical RID persists throughout, and the history of which space was authoritative when is preserved. Locus, the proposed engine operating each space, serves content; it does not get to redefine identity.

One RID, different representations

Federation also means that different people see different things. Suppose a research note in the Musewoods space is published publicly and later restricted under a policy. Its RID remains valid; a public resolver stops exposing restricted metadata, while authorized principals can still resolve it through authenticated requests. Document 08 treats this as an ordinary case and draws the conclusion explicitly: the identity lifecycle and the access lifecycle remain separate (§13.5).

What must never vary is the referent. A researcher may receive a provenance-rich view of a watershed and a visitor a simplified description, but both views are about the same watershed, 451.6R8T2W9K4M7P0Q5X. Contextual resolution may not reinterpret one RID as different resources for different users. Under the v1.1 HTTP profile, a restricted identity that may not be acknowledged produces exactly the same 404 response as an identity that does not exist, so that federation does not become a way of probing for protected resources.

Why similarity never merges identity

The hardest discipline in federation is resisting the urge to tidy up. Across three spaces there will be records that look alike: a Wellzai page summarizing Formation, a Musewoods note about formation in a garden, an RSM draft with a similar title. A federated search engine that merged them by similarity would produce cleaner results and quietly corrupt the graph. RSM ID forbids it. Similar titles, shared subjects, equivalent descriptions, or common source files do not establish that two records are the same continuing referent; where independent systems really have represented the same entity, reconciliation retains evidence and requires an authorized decision (§15.3).

The same caution applies to identifiers from outside RSM. A DOI or ORCID can be associated with an RID through relationships such as sameAs or identifiedBy, but the external identifier keeps its own authority and is never silently treated as an RSM-issued RID (§7.5). The Fieldnote Why semantic equivalence is not identity equality develops this argument with worked cases, and Why identity is not ownership explains why holding a reference to a resource, or even issuing its RID, confers no right over it.

Conclusion: share references, not databases

Following one chain of resources across three spaces shows what federation needs and what it can do without. It needs canonical RIDs on both ends of every relationship, provenance on every assertion, verified authority before any remote representation is trusted, and a registry that preserves names and bindings over time. It does not need a shared database, a common application, a single hosting provider, or an agreement that any one participant's descriptions are the truth. Each space remains, in Document 08's words, responsible for its own authoritative knowledge representations (§7.3).

For teams preparing to take part, the work is mostly a matter of habits that can be adopted before any registry exists. Record cross-organization references by RID alongside your existing links, and keep the asserting space, predicate, and authority with each one. Label cached copies with their source and retrieval time, and never present them as your own. Treat restriction as an access change rather than an identity change. And when two records look like the same thing, record the evidence and ask the authority that can decide, rather than merging them yourself.

The Viewgraph Federation across Semantic Spaces draws this chain frame by frame, and the demonstration resolver lets you resolve the Outcome Formation Model and follow its relationships into the RSM and Musewoods spaces. To revisit the parts the federation is built from, return to The Anatomy of RSM ID.