Re: Updated Policy Requirements draft

Hi Frederick,

Le mercredi 18 août 2010 à 17:16 +0200, Frederick.Hirsch@nokia.com a
écrit :
> Please review and discuss any suggested changes on the list.
> http://dev.w3.org/2009/dap/policy-reqs/

I've finally found the time to read the updated document — I think is a
clear improvement from the previous version.

A few thoughts in case we still want to work on this document (rather
than the policy work itself):
* I like the 3-levels organization, but would rename them to
  - User consent
  - Packaged permissions
  - Delegated control
The reason for this is that we would then have each of these sections
talk about something similar (the policy mechanism) rather than having
two of them talking about the object of the mechanism, and the third
talking about the mechanism. I'm also proposing control instead of
authority since the title of the document talks about control.

* relatedly, section 3 (trusted widget or application) says that trust
can be established in various ways (signature, reputation, etc); this
could be applied to Web sites as well, and so isn't widget-specific

* I would strengthen the usefulness in the entreprise environment of
what is described in section 4 (as we discussed in the London F2F),
possibly with some concrete examples.

Time permitting, I'm willing to take a stab at making these changes (and
other more editorial) if you think that's worthwhile.

Dom

Received on Monday, 6 September 2010 15:41:05 UTC