Identity answers one question:

Who are you?

Trust addresses a different one:

Why should I rely on this claim, in this context, for this purpose?

Why this distinction matters

Account takeover demonstrates the difference every day. The credentials are correct. The second factor is correct. The device is recognised. Every identity control returns "verified" — and the transaction can still be fraudulent. Identity was never wrong. It answered its question accurately. It was simply asked to carry a decision it was never designed to make.

A simple example makes the distinction concrete: a company director signs instructions to update banking details. Their identity is genuine. But they resigned yesterday. Identity remains valid. Authority does not.

Identity as one input among several

Trust Infrastructure may use identity as an input, but identity is only one component of a broader trust relationship. A full trust decision typically also depends on:

  • Authority — is this party entitled to make this claim or take this action?
  • Consent — has the relevant permission been given, for this purpose?
  • Legitimacy — is the underlying basis for the claim lawful and current?
  • Evidence — what supports the claim being made?
  • Context — is this the context the claim was established for?
  • Governance — what rules and accountability apply to how the claim is used?

None of this makes identity unimportant — it is necessary in most trust relationships. It is not, on its own, sufficient to define trust. A recipient can usually verify who sent something. It is the remaining questions — authority, consent, legitimacy, evidence, context and governance — that a trust decision still depends on.