Anchored Information
If access is sufficient, possession is unnecessary.
If custody establishes where information naturally belongs, and permission governs how others may legitimately access it, a further principle follows.
Restraint.
Restraint asks us to distinguish between what an organisation needs to know and what it needs to possess.
For generations, we have assumed that legitimate access requires information to be transferred. A document is requested, a copy is provided, and another version begins a new life within another organisation. But access and possession are not the same thing.
Where an organisation needs to view information for a legitimate purpose, access may be sufficient. Where it needs to retain information, possession may be necessary.
The principle is not to prevent possession, but to avoid unnecessary possession.
This leads to a different architecture.
Information remains anchored with its natural custodian. Appropriate access to view is granted for a defined purpose. Duration can be controlled, activity can be visible and authority can be accountable. When the purpose ends, access ends.
For the individual, control is retained rather than routinely surrendered. For the organisation, responsibility becomes more closely aligned with genuine need. Every copy that does not need to be created is one less copy to store, protect, govern and eventually delete.
Data remains anchored. Access to view replaces the transfer of data wherever appropriate.
The result is not less trust. It is trust exercised with restraint.