Don't Trust the Uniform. Verify the Mandate.
Don't Trust the Uniform. Verify the Mandate.
Last month, four men entered a home in Overijse after one of them had presented himself at the front door in a police uniform [1]. The uniform was enough and convinced the residents that they were dealing with actual police officers. The door was opened, the group moved into the house and began searching it, backed by a story that kept the residents cooperating. Only later did they become suspicious, when they noticed that the vehicle outside carried no police markings.
Incidents of this kind are not isolated, and they resurface with some regularity. The same social engineering tactic has repeatedly been shown to work in other settings as well. A high-visibility vest, for instance, is often enough to walk past a reception desk and into offices, storage areas and technical rooms without a single question being asked [2].
In this article, we look at why this type of social engineering works so well, why the identification methods we use today offer little protection against it, and how web3 technologies [3] combat this by allowing citizens to verify an identity and/or an assigned task on the doorstep, in a matter of seconds.

Main section
Quick facts
/
Verifiable Credentials and Decentralized Identifiers are W3C standards
/
A zero-knowledge proof confirms a claim without revealing the data behind it
/
A QR scan can verify a credential in seconds, offline.
/
ZKP's provide information without revealing information.
How we identify people today
In countless professional interactions, someone acting in his or her own name or on behalf of an organization has to prove to a private individual or to another organization who he or she is, and often also what mandate or assigned task he or she is there to carry out. Think of the identification of an emergency responder or a technician at someone’s home, or of physical service delivery at a company site. Today, this identification generally happens in three ways: (1) on the basis of trust (i.e., no identification), (2) on the basis of an identity document, or (3) on the basis of a “trust signal”, i.e., a non-conclusive, indicative cue, such as the presence of certain clothing (e.g., a police uniform), or a badge or e-mail issued by the organization involved:
- Relying on trust or “trust signals”. This is what happens in most situations, and it is not verification at all. The visitor is believed because the story is plausible, the clothing fits, and refusing feels impolite. Trust is precisely the surface that social engineering targets.
- Asking for an identity document. An identity document proves, at best, a legal identity. Counterfeit documents are hard to detect, and it says nothing about the function, the mandate and the time window that matter in exactly these situations.
- Asking for a badge or an e-mail. A badge is a printed trust signal, and it carries the same weakness as the uniform. An e-mail or an appointment confirmation can be spoofed or intercepted, and in larger organizations the recipient is often unable to distinguish a legitimate internal reference from an invented one.
Identification through the above means is far from ideal, since it is susceptible to social engineering and doesn’t allow full verification. But how do we prevent this type of social engineering?
A decentralized alternative
The answer is not to make the uniform harder to copy. It is to stop relying on appearance altogether, and to attach a cryptographic proof to the claim itself, supported by web3-technologies. We propose a decentralized verification system based on three building blocks.
- Verifiable Credentials (VCs) carry the claims and provide the cryptographic signature, i.e., this person, this function, this assigned task, is valid within this time window. A forged credential fails verification mathematically.
- Decentralized Identifiers (DIDs) on a blockchain provides a verifiable proof of identity of the issuer. This prevents having to contact the issuer directly.
- Zero-Knowledge Proofs (ZKPs) introduce selective disclosure. The holder is able to prove that he or she is an authorized officer of a given force, mandated for this specific intervention, and that the mandate is valid at this moment, without exposing a national registry number, a date of birth, or operationally sensitive details.
Practical Use
In practice, the verification of a person’s identity or assigned task takes place through a QR-code (or an NFC tag) that is scanned on the spot.
- Issuance. Organization A signs a VC that establishes the identity, the function and the mandate of the employee, linked to a DID on the blockchain.
- Verification. Party B, i.e., a company or a citizen, scans the QR-code and verifies the credential directly against the identity on the blockchain, without having to contact organization A. The authenticity is mathematically guaranteed. The check takes seconds, and it can be performed offline.
- Privacy. Thanks to ZKP and selective disclosure, the employee reveals only what is necessary, for example only the name of the employee, mandated for a particular task within a given time window, without surrendering all underlying personal data or commercially sensitive information.
Bottom section
Beyond the doorstep
The home invasion is the sharpest illustration of the problem, but the pattern recurs wherever someone has to demonstrate a mandate to a party that has no relationship with his or her employer. We see four broad application domains.
- Identification of employees and service providers at consumers (B2C): identification of emergency services such as the police or the fire brigade, the reading of meters at consumers by employees of energy companies, technicians and cleaning staff visiting private homes, ..
- Identification of employees and service providers at external organizations (B2B): nurses or other emergency personnel assisting in other hospitals, other companies or other countries, technical maintenance in a hotel chain or a hospital, remote operation of technical equipment at an external company, ..
- Permanent signing of documents issued by organizations or institutions: in the case of university diplomas, a credential signed once replaces the lifelong dependency on the university, which today typically results in a certificate that is either unverifiable or verifiable only through the issuing organization.
- General access control (B2B): a signed credential can be used not only for identification and verification, but also for verifiable access control. This increases the security of, for example, badge-based access systems, since it moves away from the classic centralized database and its single point of failure. A guest lecturer could book a room at an external university, and enter it, on the basis of a credential signed by his or her own university.
Sources
[1] VRT NWS, “Twee verdachten opgepakt in onderzoek naar home-invasion met valse politieagent in Overijse”, 22 August 2026: https://www.vrt.be/vrtnws/nl/2026/08/22/twee-verdachten-opgepakt-in-onderzoek-naar-home-invasion-in-over/
[2] VRT, “Factcheckers”, season 1, episode 3, “Raak je met een fluohesje overal binnen?” (2019): https://www.vrt.be/vrtmax/a-z/factcheckers/1/factcheckers-s1a3/
[3] Verifiable Credentials (VCs), Decentralized Identifiers (DIDs) on a blockchain, and Zero-Knowledge Proofs (ZKPs).
Contributors
Authors
/
Kushal Soni, Research & Team Lead, Web3/Blockchain Unit
Want to know more about our team?
Visit the team page
Last updated on: 9/11/2026
/


