# Source register

Access date for all sources: 2026-09-23.

| ID | Source | Authority / use | Material limitation |
|---|---|---|---|
| CRS-001 | [NIST SP 800-63A-4: Identity Proofing](https://pages.nist.gov/800-63-4/sp800-63a.html) | Current primary federal guidance used for the distinction among identity resolution, evidence validation and identity verification, and for minimum-necessary processing. | Governs digital identity services and credential service providers. It is not a self-storage customer-record-merging standard, legal opinion or certification basis for this tool. |
| CRS-002 | [FTC: Protecting Personal Information — A Guide for Business](https://www.ftc.gov/business-guidance/resources/protecting-personal-information-guide-business) | Current official federal business guidance used for data minimization and access-control framing. | General guidance, not legal advice and not a customer-identity decision rule. Applicable law, contracts and approved company policy control real operations. |
| CRS-003 | [NIST Privacy Framework](https://www.nist.gov/privacy-framework) | Current official voluntary framework page used only for enterprise privacy-risk-management framing. | Voluntary tool; it does not certify this article, workbook or any self-storage process. No conformance claim is made. |

## Evidence boundary

The article contains no statistic, prevalence claim, customer deployment, product capability, recognition claim or performance result. The Harbor Ridge example, identifiers, address, email strings and decisions are explicitly fictional. The sources support only the bounded principles identified above.
