TL;DR
An identity graph is not a verification system. Every claim in one was asserted by somebody, and its information content equals what that party checked and what they can take back. The vocabulary the field uses to build author identity has no field for either: schema.org sameAs is a bare co-reference claim, emitted by the party who benefits from it, with no issuer, no validity window and no revocation path.
Every system that has actually had to adjudicate authorship reached the same design: make provenance a property of the individual assertion, not of the record. ORCID did it and the numbers are brutal. Member organisations have asserted only about 9% of the affiliation claims on the registry, and institution-asserted affiliations run at just under 1% of records linked to the SCImago corpus. The infrastructure works. Almost nobody supplies it.
The operating test is revocability. Ask what would happen if the person lied, and who could take something away. An identifier nobody can revoke is an identifier nobody had to issue. And because an author identity is anchored to a person rather than a domain, the only part of it your business keeps is co-naming in records held by third parties.
The property with no source field
Open any 2026 guide to author authority and you will find the same object at the centre of it: a Person node carrying name, url, jobTitle, worksFor, knowsAbout and an array of sameAs URLs pointing at LinkedIn, X, Medium, ORCID, Crunchbase, a conference speaker page. The array is treated as the load-bearing part. Longer arrays are described as stronger identity. The word attached to the whole arrangement is verifiable.
It is worth reading what the property actually means. In the schema.org vocabulary, sameAs asserts co-reference: that this node and that URL denote the same thing. It is a statement about identity of reference, not about the truth of anything either resource says. And the vocabulary provides no way to record who made the assertion, when, on what basis, or under what conditions it should stop being believed.
What does sameAs actually assert?
It asserts that two identifiers point at the same entity, and nothing else. There is no issuer field. There is no verification status. There is no expiry. The claim is emitted by the publisher of the page, which is to say by the party with an interest in the answer, and the schema offers no slot in which a third party could countersign it. A dense sameAs array is a dense set of unsourced claims.
This is not a defect in schema.org, which was built to describe things rather than to certify them. It is a mismatch between a description vocabulary and the job the field has assigned to it. Once you see it, the standard advice reads differently. Auditing stale profile links, keeping names consistent across the byline and the bio and the markup, avoiding one author entity shared by two real people: all sensible, all about making the reference resolve cleanly. None of it is verification, and no amount of it becomes verification through accumulation.
For example: two chartered surveyors share a name, one in Bristol and one in Auckland. A sameAs array pointing at the Bristol one’s LinkedIn, X and personal site resolves the reference cleanly and correctly, and a reader following any of the three learns only what that person chose to publish about themselves. Add the RICS register entry and the same array now contains one claim a body other than the surveyor is prepared to stand behind, and would withdraw. Nothing about the first three links changed. The information content of the array roughly doubled.
What the field read into a documentation page
On 1 February 2026 Google added an Authors section to its Search Central documentation. Within weeks the section had been described across the industry as the moment author authority stopped being a soft signal and became a direct ranking factor, a reading reinforced by the March 2026 core update and by the Discover-only update that followed days after the page went live.
Two things sit awkwardly with that reading. The first is what Google’s own guidance actually asks. The people-first content documentation poses authorship as a set of reader questions: is it self-evident to your visitors who authored your content, do pages carry a byline where one might be expected, do bylines lead to further information about the author and the areas they write about. Google has been consistent for years that items of this kind are characteristics of the pages it wants to rank rather than factors it computes, and that E-E-A-T is not itself a ranking factor. Mark Traphagen, writing in January 2026, put the same point plainly: authorship is not a direct ranking factor but it strongly influences how systems interpret trust.
The second is more specific and easier to check. Google’s Article structured data documentation includes a worked example of author markup best practice. It uses name, jobTitle and url. It does not include sameAs at all. The property the field has made the centre of verifiable author identity is absent from the vendor’s own recommended example.
It is worth being precise about what author markup does buy, because the honest version is still useful. It states authorship in a machine-readable form so a parser does less guessing about who wrote what. It reduces the chance that an editor’s login gets credited with an article somebody else wrote. It makes an author page eligible for richer presentation where such presentation exists. None of those is a ranking mechanism and none of them is verification. A practitioner who sells the first three honestly keeps clients longer than one who sells the fourth.
Meanwhile the claims being circulated are the kind you should always distrust: that pages without named authors are roughly 40% less likely to be cited by AI engines, that sites adding structured author pages saw measurable ranking improvements within weeks of a core update. These are correlational at best, and the confound is obvious. Organisations that build author infrastructure are organisations investing in content and acquisition generally. If you want a number you can defend, it will not come from that literature; the same problem afflicts most claims about what drives AI product recommendations.
The issuer is the whole story
Reframe the question. Instead of asking how many profiles your author graph connects, ask of each node: who issued this, what did they check, and what can they take back?
That third question is the one that does the work, because revocation is the only observable consequence of a verification actually having happened. If a claim turns out to be false and nothing can be withdrawn, then nothing was ever checked and nothing was ever staked. Which gives the rule this article is built on: an identifier nobody can revoke is an identifier nobody had to issue.
THE ISSUER AUDIT
| Identifier | Who issues it | What they actually checked | What they can revoke |
| Your own author page | You | Nothing. It is a statement of intent about your own staff | Nothing |
| A self-service platform profile | You, at signup | An email address, and in most cases not even that | The account. Never the claim the account makes |
| A platform verification badge | The platform, via an ID vendor | A government ID matched to a selfie, or a code sent to a work email | The badge. Note the holder can also remove it at any time |
| An ORCID iD with self-entered detail | ORCID issues the iD, you supply the claims | An email address. The affiliations are typed in by the holder | The iD, not the affiliation attached to it |
| An ORCID trust marker | The institution, via the Member API | HR, registrar or research-office records, through an authenticated workflow | The affiliation assertion itself |
| A CAWG identity assertion | A certificate authority, or an identity aggregator | Legal identity of a person or organisation, or merely that a provider saw you control an account at a stated time | The certificate or the credential |
| A statutory register entry | The regulator | Qualification, competence and continuing fitness to practise | The right to practise, and the protected title with it |
Two rows are green. In a typical author graph they are also the two rows nobody has populated, because they are the only two that require somebody else to do something.
Does a knowledge panel verify an author?
No. A knowledge panel is Google’s own inference about an entity, not an attestation by a third party. It is assembled from what Google has read, can be claimed but never issued, and can be withdrawn without notice. That makes it revocable by exactly one party, who checked nothing about the author’s competence. Panels are a good diagnostic that resolution has succeeded. Treated as a credential they invert the audit above, because the most visible identity artefact in search is the one nobody staked anything on.
What ORCID learned the hard way
Scholarly publishing has been running an author identity system at scale for over a decade, under adversarial pressure, with real consequences for getting it wrong. It is worth studying because it made exactly the mistake the marketing world is making now, noticed, and fixed the data model.
An ORCID record has always let the holder assert almost anything about themselves. The fix was not to police the claims. It was to record, per assertion, who put it there. ORCID calls the resulting distinction a trust marker: an item validated by a member organisation rather than self-reported. The recognised categories are affiliations validated by universities and research institutions, funding awards validated by funders, works validated by publishers, and more recently verified institutional email domains derived through ROR. The design principle is stated explicitly in ORCID’s own material: by recording and disclosing the provenance of every assertion, consumers of the data can judge veracity for themselves.
The verified institutional email domain deserves singling out, because it is the cheap middle path and the one most transferable outside academia. The holder proves control of an address, ORCID publishes only the domain part rather than the address itself, and the domain resolves against ROR. The holder does the work, but the backing comes from whoever controls the domain, which is not the holder. That is the structural trick worth copying: find the assertion where somebody else’s infrastructure does the vouching without any of their time being consumed.
The numbers are the argument
Nearly 4.2 million ORCID records carry an affiliation, about a third of the registry. Member organisations added roughly 9% of them. Around 2.9 million active records have a verified institutional email domain. And the joint SCImago Labs and ORCID study published in February 2026, which analysed patterns across 9,720 institutions, found that institution-asserted affiliations account for just under one percent of ORCID records linked to the SCImago corpus, while still correlating significantly with research visibility and ranking position.
Read those two figures together. The most mature author identity infrastructure in existence, purpose-built for exactly this problem, with a provenance field on every claim and a membership API for institutions to fill it, is running at roughly one percent institutional backing. The plumbing was never the constraint. Somebody with something to lose has to be willing to make the assertion, and mostly they are not asked.
Key takeaway
The lesson is not that ORCID failed. It is that ORCID measured the thing everybody else leaves unmeasured. If your author markup carried a source attribute per claim, the honest value for almost every entry would be self. That is the number the field is avoiding by not having a field for it.
Inside the provenance stack: two doors, one of them decorative
The provenance ecosystem has already built the thing the SEO world is gesturing at, and its construction is instructive. The Creator Assertions Working Group, which extends C2PA with human-generated metadata, publishes an Identity Assertion specification. It lets a named actor prove control of a digital identity and document their role in an asset’s lifecycle, bound cryptographically inside the manifest. Its UX guidance reached ratified 1.0 status on 5 February 2026 and explicitly deals in trust hierarchies and verification status, which tells you the authors understood that not all identity claims are worth the same.
Critically, CAWG identity assertions require secure digital credentials. An authorship claim cannot simply be typed. There are two supported routes, and they are not equivalent.
Door one: a certificate somebody validated
An X.509 certificate issued by an authorised certificate authority, intended for enterprises, publishers and news organisations. Commercially this looks like tiered products at roughly fifty to a hundred dollars a year, split by whether the CA validated an individual, an organisation, or both. What you are buying is somebody else’s validation work and their exposure if they did it badly. That is a real credential with a real issuer and a real revocation path, and it is why this route costs money while emitting metadata is free.
Door two: a notarised login
The alternative is an identity claim aggregator. The credential is issued by the aggregator under a did:web rooted in a domain the aggregator controls, and its payload is a verifiedIdentities array. Each entry records a username, a URI, a verifiedAt timestamp and a provider. Parse that honestly and the assertion is: at this moment, this provider observed that this account was controlled by whoever was holding it.
That is a notarised login. It is genuinely useful for what it is, which is binding a social presence to a manifest in a tamper-evident way. It is not a statement about the person, their competence, or their authorship of any argument. Work was underway in early 2026 to add W3C Verifiable Credentials and verifiable legal entity identifiers to the supported set, with CAWG offering no guarantee about when or whether. Until then, the aggregator door carries the same evidential weight as the profile it wraps.
The badge you can delete
The most linked node in any real author graph is LinkedIn, so its verification semantics matter. As of 2026 there are three categories. Identity verification runs through CLEAR in the United States, Canada and Mexico, Persona in sixty-plus countries and DigiLocker in India, and matches a government ID to a live selfie. Workplace verification runs through a code to a work email, Microsoft Entra Verified ID, or a company-provided Learning or Recruiter licence. Education verification exists in reduced form, with new institutional verifications reportedly paused from April 2026. More than 100 million members have verified identity or workplace, against a base of over a billion, and workplace verification accounts for around 60% of verified profiles.
Two properties matter more than the coverage. Workplace verification is the member confirming their own association using an address or licence they already hold, not the employer attesting to anything. And verification is free, optional, and removable by the holder at any time. A credential whose revocation control sits with the subject is not a credential a third party issued. It is a self-assertion with a better typeface.
The Revocation Question
Four questions, per identifier, before it earns a place in your markup.
1. Who issued this, by name? If the answer is your organisation or the author, stop here.
2. What did they check, stated as one sentence? Write the sentence. Most come out as a matched document or a delivered email.
3. What happens to it if the claim turns out to be false? If the answer is nothing, no verification occurred.
4. Who else can see that it was withdrawn? A revocation nobody can observe is not a revocation.
And the companion rule, THE NARROWEST PREDICATE: a chain is only as informative as the narrowest thing any link in it actually establishes, never as authoritative as its strongest issuer. A CA validating a legal name does not thereby vouch for a building-safety opinion.
The part that walks out of the door
Here is the consequence nobody in this discipline wants to price. An author identity accrues to a person. The knowledge panel, the ORCID record, the citation footprint, the credential chain, the accumulated co-occurrence in an engine’s representation of a topic: all of it is attached to a human being who can resign. A backlink cannot resign.
This makes author authority structurally different from every other asset a link builder builds, and the difference is not addressed by any amount of markup on your own domain. You cannot own a person’s identity. What you can do is be co-named alongside them in records held by other people, because a document that names both the individual and the organisation is the only artefact that ties the person’s accumulating identity to your entity in a place you do not control and cannot lose access to.
That reframes the acquisition brief. A byline on a contributed article names the person and gives the host the placement; it issues nothing and, in the terms above, is not a credential at all, which is worth remembering the next time guest posting is presented as an authority play. A named quote in a trade title, a named seat on a standards committee, a named consultation response published by a regulator, a named entry in a professional body’s member directory: each is a third-party record naming a person and an organisation together, and several of them are also revocable by their issuer. The overlap between local citations and register-style listings and genuine credential issuance is larger than the field has noticed.
The Co-Naming Rate
Make it countable. Take the distinct third-party sources that mention your organisation across a fixed sample, either your top 150 referring domains or the sources cited across 40 to 60 monitored prompts. Count how many name at least one specific individual alongside the organisation. Divide.
Under 15% and the identity equity you are funding is accruing entirely to individuals; the organisation is a backdrop. Between 15% and 35% is the common case for a firm that has run an author programme on its own domain only. Above 35% and the person and the entity are genuinely bound in the public record. The figure moves slowly, which is what makes it worth tracking rather than a one-off audit, and it degrades on its own every time somebody senior leaves. Pair it with whatever you already use for measuring entity authority rather than replacing it.
Key takeaway
A backlink is an asset with a fixed owner. An author identity is an asset with a mobile one. Read the Co-Naming Rate as the share of your identity investment that would survive a resignation letter, and for most firms running an author programme on their own domain that share is under a fifth.
There is a defensive edge to this as well. A well-resolved author entity is a target. Once a person is unambiguously bound to a topic and an employer, fabricated bylines, cloned profiles and content published in their name all become cheap and effective, and the damage lands on an individual’s public record rather than on a domain you can disavow. Resolution cuts both ways: the same clarity that lets an engine attribute your work correctly lets it attribute somebody else’s work to you. A firm that builds author entities without a monitoring routine for its people’s names has built a liability alongside the asset.
One practical note on the plumbing before the example. Author markup injected by JavaScript is supported by Google, but a growing share of the crawlers that matter for citation do not render at all, so server-side rendering remains the safer default. If your author entities exist only after hydration, the audit above is measuring something most retrieval systems never see, which is the same failure mode that makes JavaScript-dependent backlinks unreliable, and the same reason machine-readable feeds outperform clever front-end work.
Worked example: Calverley and Roan
Calverley and Roan is a Newcastle architecture practice with about 8.2 million pounds in fee income, 34 staff and 19 architects on the statutory register. Its technical library on Building Safety Act gateways and staircase requirements had become a significant source of enquiries.
In January 2026 the practice commissioned the full author-authority programme: 14 weeks, about 31,000 pounds, 19 author pages, Person markup with sameAs arrays averaging six profiles per author, knowsAbout arrays, a knowledge panel push for the two founders, and ORCID iDs for the four staff who had published academically.
What it bought and what it did not
Entity resolution genuinely improved. Both founders acquired knowledge panels. A persistent confusion with a same-named architect in Australia stopped. Naming across 60 monitored building-safety prompts moved from 9 to 11, which is noise.
Then they ran the Issuer Audit across all 114 sameAs targets. Ninety-seven were self-service profiles. Thirteen were the practice’s own pages. Four were revocable by a third party: three register entries and one chartered-practice listing. Sixteen of the 19 architects had no link to the statutory register that licenses the protected title they trade under, for the mundane reason that the agency template had no field for it. The single most revocable credential each of them held, issued by a regulator that can withdraw their right to call themselves an architect, was missing from a project whose stated purpose was verifiable identity.
The second programme
Register links went in for all 19. The chartered-practice listing was added. Then the work that mattered: their Co-Naming Rate was 12%, meaning that of 176 third-party sources mentioning the practice, only 21 named an individual alongside it.
Over the following twelve months they submitted consultation responses under named architects, took two named seats on a standards committee, and put two specialists on standing availability for on-record technical comment. The Co-Naming Rate went from 12% to 38%. Naming across the 60 prompts went from 11 to 29. Two invited-tender shortlists cited the committee seat by name. The mechanism is the one behind newsjacking as an earned-media tactic and behind sourcing platforms like Connectively and its successors; what changed was the brief, not the channel.
The costs that belong in the case study
In September one of the two founders left to start a competing practice, taking a knowledge panel, an ORCID record and a personal citation footprint the practice had paid to help build. Naming fell on eight prompts for roughly two months until a successor’s committee seat was recorded. That is the portability problem arriving on schedule, and no markup on the practice’s domain slowed it down.
Second, naming individuals on compliance guidance concentrated professional exposure. The professional indemnity insurer asked for the review workflow in writing, and named architects became the addressable target for complaints rather than the firm. Third, two of the 19 declined to be named on Building Safety Act content at all, which is a defensible professional judgement and left the two highest-value topics thin. Fourth, one register link went stale when an architect’s registration lapsed over a fee-payment administrative failure, leaving a markup property pointing at a page stating the person was not currently registered. That ran for five weeks and was materially worse than having no link, because a revocation that actually fires is legible in a way an absence never is. If you have read the analysis of signed and unsigned content credentials, the shape will be familiar, though the mechanism here is a live withdrawal rather than a broken chain.
Where this argument is weakest
The strongest objection is not that credentials are coming. It is that resolution was always the job, and sameAs does resolution well. If an engine’s real difficulty is telling one James Wright from another, dense self-emitted co-reference links help enormously, and they help precisely because nobody needs to verify them: a co-reference claim is cheap to check against the target. Does the profile name match, does it link back, does the biography agree. Reciprocity turns a bare assertion into a two-sided one without any issuer at all. Criticising sameAs for not verifying is on this reading criticising a hammer for not being a saw.
That is correct, and it is the best defence of the current playbook. Four bounds.
One: resolution is a threshold good, not an accumulating one. Once the entity resolves unambiguously, the next six profile links add nothing. The playbook sells identity markup as a signal that compounds. It behaves like a gate you clear once, which is exactly what Calverley and Roan bought for 31,000 pounds.
Two: reciprocity is only available on the least informative nodes. You can link back from a platform profile because it is your profile. You cannot make a regulator’s register link back to you. So the reciprocity test systematically prefers self-service nodes and penalises exactly the issuers whose assertions carry weight.
Three: resolving to something empty resolves you to nothing. Resolution has value only where the resolved entity carries a revocable claim. A perfectly disambiguated author who is verified nowhere is a well-identified unknown.
Four: the outcome attributed to sameAs is not observed in the vendor’s guidance. It is absent from Google’s own author markup example, and the studies asserting citation gains are correlational with an obvious confound. That does not make the practice wrong. It makes the case for it unproven, and it means the marginal pound is better spent where the claim is falsifiable, which is also the honest position on most AI citation recovery work.
The second objection: the wallets are coming
Real credential infrastructure is arriving on a legal deadline. Under eIDAS 2.0, all 27 EU member states must offer citizens a European Digital Identity Wallet by the end of December 2026, with regulated private-sector acceptance mandated by December 2027. The architecture framework reached version 2.8 in April 2026, wallets can carry professional qualifications alongside identity documents, and the Digital Credentials API shipped enabled by default in Chrome 141 with Safari support alongside it. This is authority-issued, revocable, cryptographically verifiable identity at population scale.
It will change what a human counterparty can check inside a transaction, and it is worth watching if you operate in European markets or across multiple jurisdictions. It will do very little for retrieval. A wallet credential is presented, selectively, under the holder’s exclusive control, to a relying party in a session. It is not published. A crawler fetching your author page receives no presentation and no attribute, and the holder is entitled to decline. The open web will still be read off pages, which means the countersigning that matters for citation will still come from third parties choosing to write your people’s names down. Proof of personhood, similarly, will establish that a human exists. It will never establish that a human wrote.
What to do on Monday
Roughly two weeks of work, most of it not content production.
- Run the Issuer Audit. List every sameAs target across every author. Mark each self-issued, platform-issued or authority-issued. Expect the third column to be nearly empty; that emptiness is the finding.
- Add the register entry for every credentialed person you employ. Statutory registers, chartered bodies, licensing rolls. This is the cheapest genuine credential most firms already hold and habitually omit, and it is usually a five-minute template change.
- Ask your institutions to assert. If your people hold ORCID iDs, ask the affiliating institution to add the affiliation through its membership, rather than typing it in. This is the difference between a claim and a trust marker and it costs you an email.
- Apply the Revocation Question to anything a vendor sells you as identity verification. Four questions. If nobody can name a party who could withdraw the thing, you are being sold a link and not a credential.
- Calculate your Co-Naming Rate. One number, one afternoon, over your top 150 referring domains. Re-run it quarterly, because it decays whenever somebody leaves.
- Screen prospects for whether they issue anything. Add a column to the prospecting sheet: does a placement here create a third-party record naming a person, and can the host withdraw it? Directories, member registers, committee rosters and speaker lists score better than they look on any authority metric, and better than most sponsorship placements.
- Render your author markup server-side and confirm a non-rendering fetch still sees the Person node. If it does not, none of the above reaches the systems you built it for.
- Write down who is exposed. Naming individuals moves professional risk onto them. Tell them, get the review workflow documented, and expect some to decline. A refusal is legitimate and should change the topic plan, not the person.
- Watch for impersonation. A well-resolved author entity is a target; fabricated bylines and cloned profiles are now a routine tactic, and the defensive posture overlaps with negative SEO defence and with spam link detection.
The reframe is small. Stop asking how well your authors are described and start asking who, other than you, has staked anything on them being who you say they are. That question has a short answer today for almost every organisation, and the short answer is where the opportunity is. For the wider context on how corroboration compounds into visibility, the 2026 link building statistics and the strategy guide set the baseline, the beginners guide covers the fundamentals, and the tools roundup covers what can and cannot be automated. Agent-driven browsing will make the issuer question sharper still, for the reasons set out in the analysis of agentic browsing and click value.
