







don't think i'm worried about this in particular, but it does make me wonder what exactly is the credible exit for my own data if a space authority becomes malicious and stops issuing me credentials? (still wrapping my head around the permissioned data proposal so sorry if this is a dumb question!)
Andrew Lisowski 💻
I really worry that permissioned data is gonna kill a lot of stuff Take my recipe app: If i wanted no one to have access to the records but my app all i have to do is 1. create a space 2. use that space for all user content Bam, now no open data
Jul 20, 2026 at 7:36 PM
Permissioned Data: Space Access - Nick's Blog
Stepping outside the shapes series for a deep dive: how space configuration decides which people and which apps get credentials. Here be dragons.
Credible exit
To avoid lock in, you need the ability for the user to credibly exit.

A Duty of Loyalty for Privacy Law
Data privacy law fails to stop companies from engaging in self-serving, opportunistic behavior at the expense of those who trust them with their data. This is a
Who owns your data?
A Supreme Court case about a bank robbery could redefine your digital rights.

I Asked 100 Companies for My Data. I Got Deletion Notices Instead
California residents have a legal right to access the data that companies collect about them. Actually exercising that right is a burdensome nightmare.

A Landscape Survey of Private Digital Credentials
CJ Larkin and Renée DiResta examine digital ID endeavors to understand what drives adoption, what facilitates trust, and how privacy and security trade off.

research.latha.org
A permissioned appview for research documents on AT Protocol. True data ownership with optional monetization.
A deep dive on permissioned-data space access. The dials, policies, and the difference between handing out keys and revoking them.
Permissioned Data: Space Access
ngerakines.leaflet.pubThere is one area with Permissioned Data Spaces that I haven't seen discussed. It reveals that data is currently stored in the (I think I'm coining a term here) *Public Space* on Personal Data Servers. Remember, most people on Bluesky aren't aware of where their data is stored, or what that means.
@dholms.at thinking about permissiones data. What if: Permissioned data URI was at://<PDS did>/<record type>/<rkey> exactly the same as public data. The PDS would handle the space assignment opaquely and do a 4xx response with some space aturis. Client goes and grabs a space cred and retries
How can a lay person "own their data" if they have no idea what a PDS is and that they are granted authority over that server and it's data? The idea that they only need to know about "credible exit" if bluesky becomes hostile plays right into the computationally passive cycle we live in.
𝕮
”The distinction between programmer and user is reinforced and maintained by a tech industry that benefits from a population rendered computationally passive. If we accept and adopt the role of less agency, we then make it harder for ourselves to come into more agency.”
here it is folks! lots of details to still nail down, but this is roughly where our heads are at for the design of a permissioned data protocol give it a read and let me know your thoughts!
Permissioned Data Diary 4: The Big Picture
dholms.leaflet.pubSixth in the permissioned data series: what spaces do to feeds. The firehose stops at the space boundary, the credential flow becomes your membership source-of-truth, and one feed URI serves a different skeleton to every viewer.
Permissioned Data Shapes: Feeds
ngerakines.leaflet.pubAye > Data Ownership as a conversation changes when data resides primarily with people (..). > Instead of arguing for what kinds of data we ought to be able to download from the corporate silos, the platforms should be asking us what kinds of data they may copy from *our* servers.
Erlend Sogge Heggen
The web can be made personal again. blog.muni.town/personal-data-storage-idea/