LER & TRUSTED WORKFORCE INFRASTRUCTURE WORKSHOP MODULE

Individual Control, Permissions & Data-Use Boundaries

Clarify what people choose to present, why other exchanges occur, and what recipients may do with the information—so control and its practical limits are understandable.

Does this sound familiar?

“Sharing” describes several different actions

Presenting a record, enabling continuing access, transferring a copy, and authorizing an organizational exchange are treated as though they create the same arrangement.

The purpose is too broad to understand

People are told their information supports “opportunities” or “services” without a clear account of who receives it and what the recipient intends to do.

Recipients receive more than they need

An exchange includes an entire profile or supporting history when the selected decision requires only a narrower set of information.

A permission screen hides later responsibilities

The interface asks for a choice, but partners have not clarified retention, onward disclosure, access by staff, or other downstream uses.

Withdrawal promises exceed what can happen

People expect a stopped connection or revoked link to remove information already downloaded, retained, or used elsewhere.

No one owns the difficult questions

A person asks who has their information, whether a use is appropriate, or what can be withdrawn and is passed between platforms and organizations.

What are individual control, permissions, and data-use boundaries?

Individual control concerns the meaningful choices a person can make about presenting their information and managing supported access arrangements.

Permissions describe which actions an exchange allows, for which information, recipients, purposes, and conditions.

Some exchanges begin with a person choosing to present a record. Others arise through an organizational process whose authority and requirements need to be identified separately.

Data-use boundaries clarify what happens after information is received, including access, retention, further use, onward disclosure, and responses to changed preferences or concerns.

This module examines those distinctions within a selected exchange so the arrangement can be explained, reviewed, and implemented without promising control that partners cannot deliver.

A sharing choice should describe what will actually happen.

A person may understand “share” to mean allowing someone to view a record once.

The receiving workflow may instead create a retained copy or make the information available to several staff roles.

An ongoing connection may behave differently from a downloaded document.

The workshop makes those differences explicit.

Partners examine what the person can choose, what the receiving organization is responsible for, and which actions remain possible after the exchange.

That gives the group a clearer basis for designing understandable choices and accountable follow-through.

Where control and permissions can become unclear

The individual’s choice

Information selected
Intended recipient
Purpose presented
Available alternatives
Assistance with the choice

The exchange arrangement

Presentation or transfer
One-time or continuing access
Authority for the exchange
Conditions and duration
Actions outside the choice

Recipient responsibilities

Intended use
Authorized staff access
Further interpretation
Onward disclosure
Response to concerns

Retention and withdrawal

Copies created
Retention expectations
Stopping future access
Requests concerning retained information
Practical limits

Review and accountability

Responsible organizations
Explanations and notices
Recorded choices or authority
Change review
Support and escalation

The review focuses on one selected exchange. It does not assume that every information flow uses the same authority, permission, or technical control.

How this module helps

Separate the exchange arrangements

Distinguish a person presenting information from continuing access, transferred copies, and other organizational exchanges.

Clarify purpose and scope

Identify the information and recipients needed for the selected use and make unnecessary access or disclosure visible.

Define recipient responsibilities

Examine what happens after receipt, including access, retention, additional uses, and responses to concerns.

Make control and its limits understandable

Specify what can be changed or stopped, what requires a request to another organization, and what cannot be promised.

The choice on the screen is only part of the arrangement.

A person may choose to present a credential to a workforce partner.

That action does not explain whether the recipient retains a copy, who can access it internally, or whether another organization will receive it.

The workshop connects the initial choice to those receiving responsibilities.

Example: “I stopped sharing the link. Why does the organization still have my record?”

A participant presents a record through a link.

The receiving organization retains a copy within its application process.

The participant later disables the link and expects the earlier copy to disappear.

Partners examine the distinction between stopping future access and addressing information already received, then define clearer explanations and an accountable request route.

Questions to review together

What can the individual select, understand, decline, or change in the proposed arrangement?

What is the exchange intended to support, and which information is necessary for that purpose?

What authorizes each information flow, and which conditions need confirmation by the responsible organization?

Who receives the information, who can access it, and what uses or further disclosures are contemplated?

What is retained, what can be stopped, and how are requests concerning earlier copies handled?

Who explains the arrangement, answers concerns, and reviews changes to its purpose or boundaries?

What needs to connect?

The selected information

The records, claims, or contextual details involved in the exchange.

The individual’s choice

The action the person is being asked to take and the options genuinely available to them.

The purpose and authority

Why the exchange occurs and the basis the responsible organizations rely on for it.

The receiving responsibilities

The people, organizations, and processes responsible for appropriate use after receipt.

The retention and access arrangement

What remains available, for how long, and under whose control.

The change and concern route

How preferences, withdrawal requests, questions, and potential misuse are addressed.

When “consent” substitutes for a complete arrangement

Partners may rely on a broad choice without clarifying what follows.

  • Different information flows are bundled together.
  • Purposes remain vague.
  • Entire records are requested without a defined need.
  • Recipient access and further use are unexplained.
  • Stopping a link is presented as removing every copy.
  • Concerns have no responsible owner.

The person may agree to something that behaves differently from what they understood.

When choices and responsibilities are explicit

Partners can explain the exchange in practical terms.

  • Presentation, transfer, and continuing access are distinguishable.
  • Purposes and recipients are identified.
  • Information scope follows the selected use.
  • Receiving responsibilities are documented.
  • Withdrawal explanations reflect actual capabilities.
  • Questions and requests have an accountable route.

The arrangement gives people and organizations a clearer understanding of what they can expect.

A practical example

A workforce program wants participants to present preparation records to an employer.

The selected receiving use is reviewing completed training during an application.

The workshop identifies the credential and contextual details needed for that review.

Partners distinguish the participant’s presentation from any separate information exchange between the program and employer.

They examine whether the employer receives a retained copy or temporary access and which staff roles need to use it.

The group identifies additional proposed uses that are outside the initial application review and assigns them for separate consideration.

Next, partners consider what happens if the participant stops an ongoing connection.

They define which future access ends and how a request concerning an earlier retained copy reaches the responsible organization.

The proposed explanation describes those differences in language a participant can understand before presenting the record.

The resulting brief connects information scope, purpose, authority, recipient responsibilities, and support without promising that a single control can govern every downstream action.

Individual presentation and organizational exchange need separate explanations.

A person may choose which record to present to a particular recipient.

An organization may also operate other information flows for a defined program or administrative purpose.

The workshop does not assume that one choice covers both arrangements.

It identifies each relevant flow and the organization responsible for explaining its authority and conditions.

Questions requiring policy or legal interpretation become assigned confirmation tasks.

That makes the boundaries clearer without treating every exchange as either entirely optional or automatically authorized.

Stopping future access is different from retrieving information already received.

A supported control may stop a link, connection, or future presentation.

A recipient may already hold a copy or have used the information within its process.

The workshop examines those circumstances explicitly.

Partners identify what can happen through a technical control and what requires action by a receiving organization.

They also clarify what explanation and response route a person should receive.

The purpose is to describe real control accurately and make responsibilities visible where technical control ends.

WORKSHOP MODULE 7

Individual Control, Permissions & Data-Use Boundaries

This module is a focused minicourse and working session within the LER & Trusted Workforce Infrastructure Workshop.

Your team learns to distinguish individual presentation, exchange authority, recipient use, and withdrawal, then applies those distinctions to a selected information flow.

The work produces a reviewed starting point for understandable choices, accountable boundaries, and a supporting product configuration.

Individual Control, Permissions & Data-Use Boundaries — Make the Sharing Arrangement Clear

What this module can address

The selected scope may include:

The workshop selects the questions that materially affect the defined exchange.

What kinds of responses might emerge?

The response depends on the gaps uncovered in the selected example.

A clearer presentation choice

Explain the information, recipient, purpose, and available options before the person acts.

A narrower information request

Reduce the proposed exchange to the records and context needed for the selected use.

Separate exchange descriptions

Distinguish individual presentation from other information flows with different authority or conditions.

Explicit recipient responsibilities

Identify access, use, retention, further disclosure, and response obligations requiring confirmation.

An accurate withdrawal explanation

Describe what can stop, what may already have occurred, and where requests about retained information should go.

A focused configuration brief

Specify the choices, access arrangements, explanations, records, and support routes a subsequent implementation would need.

Some responses may involve clearer wording or a smaller information request. Others may require changes to organizational processes, agreements, policies, or technical controls.

What we review together

The selected information flow

What moves, between whom, through which arrangement, and for what purpose.

The individual experience

What the person is told, what they can choose, and how they receive assistance.

The authority and conditions

Which responsibilities and requirements apply to each flow and who can confirm them.

The receiving process

Access by staff, intended use, retained copies, and any contemplated further disclosure.

Changes and withdrawal

What can be changed or stopped and how earlier receipt or use affects the response.

Accountability and explanation

Who maintains the arrangement, answers concerns, and reviews proposed changes.

The working exercise

Follow one sharing choice beyond the moment of presentation.

Choose a representative exchange in which a person presents information or partners transfer information about them.

STEP 1

Describe the flow

Identify the information, sender, recipient, purpose, and intended benefit.

STEP 2

Identify the choice or authority

Separate what the person chooses from other conditions or authorities that need organizational confirmation.

STEP 3

Examine the information scope

Determine which records and context the receiving use needs and what can be excluded.

STEP 4

Trace what happens after receipt

Identify access, copies, retention, further use, and other recipients requiring review.

STEP 5

Test a changed preference

Consider withdrawal, stopping access, or a request about an earlier copy and define the practical response.

STEP 6

Assign explanations and responsibilities

Capture the wording, owners, confirmation tasks, and configuration requirements needed to make the arrangement understandable.

The exercise produces a reviewed control, permissions, and data-use brief for the selected example.

CONNECTING THE WORKSHOP TO A POSSIBLE GOBEKLI SETUP

Make individual choices and organizational responsibilities visible.

The workshop can help define how a subsequent Gobekli implementation would support the selected exchange across TalentPass, TalentSync, Passport Pages, and participating systems.

Depending on confirmed scope and product availability, the configuration brief may describe:

  • Records and contextual information within scope.
  • Individual presentation choices.
  • Named recipients or defined recipient roles.
  • Purpose explanations and relevant conditions.
  • Distinctions between presentation, transfer, and continuing access.
  • Access duration and supported change controls.
  • Recipient responsibilities requiring confirmation.
  • Information about retained copies and downstream limits.
  • Records of relevant choices or exchange authority.
  • Support, withdrawal-request, and escalation routes.

The workshop clarifies the behavior and explanations required before implementation is proposed.

Specific permission controls, presentation methods, access restrictions, retention functions, activity records, and integrations must be confirmed separately against current product availability and partner requirements.

SCOPE AND BOUNDARIES

A focused review of control within the selected exchange.

The module begins with the use case defined through Workforce Infrastructure Direction.

It examines individual choices, information scope, organizational responsibilities, and the practical limits of controlling information after receipt.

It does not automatically establish or deliver:

  • Legal authority for an information exchange.
  • A compliance determination or legal opinion.
  • Permission covering every possible future use.
  • Complete individual control over every organizational record.
  • Removal of every previously received copy.
  • Reversal of decisions already made using information.
  • Enforcement of every downstream responsibility.
  • Production permissions, retention controls, or integrations.

Responsible policy, privacy, legal, or operational representatives may need to confirm the proposed arrangement.

Questions about identity, wallet access, security, AI use, and continuing governance connect to their respective modules when they affect the selected use case.

What should you bring?

One representative information flow and the explanation currently given to the individual are enough to begin.

Use fictionalized or appropriately redacted materials where practical.

Helpful starting materials

The workshop can identify missing explanations and unresolved responsibilities without collecting participants’ actual records.

What can you leave with?

An information-flow and control map

The selected records, recipients, purposes, choices, and other exchange arrangements.

A permissions and responsibilities brief

The conditions, organizational confirmations, and receiving responsibilities that need to be explicit.

A retention and withdrawal outline

What remains available, what can be stopped, and how requests concerning earlier copies or uses are handled.

An explanation and configuration brief

Participant-facing wording, support routes, responsible owners, and requirements for a subsequent implementation.

These outputs begin with the example reviewed during the module. Final scope depends on the modules selected, available inputs, and the exchange established through Workforce Infrastructure Direction.

Where might the work lead next?

Wallet Portability, Accessibility & Assisted Use

Examine whether people can understand and act on their choices across supported wallet, presentation, recovery, and assistance arrangements.

Security, Procurement & Integration Readiness

Translate the proposed boundaries into technical dependencies, review questions, and implementation requirements.

Shared Governance, Funding & Operational Sustainability

Establish continuing ownership, partner responsibilities, change review, and support for the selected exchange.

These modules extend different parts of the work. Selection depends on the problem and decision established through Workforce Infrastructure Direction.

Frequently asked questions

Questions organizations ask before beginning.

It addresses unclear choices and responsibilities around presenting, exchanging, receiving, retaining, and further using workforce information. The focus is one selected exchange.

The foundation identifies the information flow, participating organizations, intended benefit, and receiving decision. Those choices establish which permissions and boundaries need review.

Individual control includes the practical choices and supported actions available to a person. A consent choice may be part of an arrangement, but it does not explain every receiving responsibility or technical limitation by itself.

The module does not assume that it does. Partners identify the authority and conditions for each relevant flow and assign questions to the representatives responsible for confirming them.

Presentation may involve a particular record at a particular moment. Continuing access may allow later retrieval or updates. The workshop clarifies which arrangement is proposed and what the person can change.

That depends on the receiving workflow. The module examines what actually happens and what the individual should be told.

Yes. The exercise reviews which records and context the selected receiving use needs and identifies information that can be excluded.

Describe the recipient, the information requested, and the process or decision it is intended to support. The workshop can test that explanation against the proposed flow and identify overly broad wording.

That proposed use needs its own review against the applicable authority, conditions, and responsibilities. The workshop makes it visible rather than assuming the original arrangement covers it.

The practical response depends on the arrangement and what has already occurred. The module distinguishes stopping future access from requests concerning retained copies or earlier uses.

The workshop does not assume that it does. Partners need to explain the supported control and define a separate route for questions or requests involving information already received.

Identify what the receiving organization retains, why, and who can confirm the applicable requirements. The workshop records those questions and responsibilities without making a legal determination.

The module can examine assistance, including how to explain options and preserve the individual’s appropriate role. Authority to act on someone’s behalf is a separate question requiring confirmation.

No. It produces a concrete description of the exchange and its unresolved questions that responsible specialists can review.

This module examines choices, purposes, permitted uses, and responsibilities. Security work examines how the relevant systems and controls protect the arrangement. Both may be needed for implementation.

The outputs can inform presentation choices, permission explanations, access arrangements, and support requirements in a subsequent Gobekli configuration. Specific capabilities and integrations must be confirmed separately.

Partners can confirm authority and responsibilities, revise explanations, narrow information requests, and scope supported controls. Related modules can address wallet use, security, or ongoing governance.

BUILD A MORE UNDERSTANDABLE AND TRUSTWORTHY EXCHANGE

Make clear what people can choose—and what happens after information is received.

Individual Control, Permissions & Data-Use Boundaries helps your team connect meaningful choices to explicit purposes, receiving responsibilities, and realistic limits.

Begin with Workforce Infrastructure Direction, then combine the modules that address the questions your participating organizations need to resolve.