Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

ORCID Trust Markers: Institution-Asserted Affiliations and Verified Email Domains

ORCID Trust Markers distinguish institution-verified affiliations and verified email domains from self-asserted profile data. This guide covers how institution-asserted affiliations flow through the ORCID Member API and Affiliation Manager, how verified email domains work via ROR, and why the distinction matters for institutional research visibility and CRIS data quality.

An ORCID record can contain two very different kinds of data, even though both look identical on the page at first glance: information the researcher typed in themselves, and information a trusted organization pushed to the record and vouches for. ORCID calls the second kind a Trust Marker. Trust Markers are the visual and structural signal that distinguishes institution-verified data from self-reported data on an ORCID record, and they matter directly to anyone building institutional research profiles, feeding a CRIS, or evaluating how much weight to put on an ORCID-sourced affiliation claim.

This guide covers what Trust Markers are, how institution-asserted affiliations get onto a record via ORCID’s Member API and Affiliation Manager tool, how verified email domains work as a newer, privacy-preserving Trust Marker, and why both matter for institutional research visibility. For background on the identifier itself, see CASRAI’s ORCID iD entry; this page assumes familiarity with what an ORCID iD is and focuses specifically on the trust layer built on top of it.

What Are ORCID Trust Markers?

According to ORCID’s own documentation, Trust Markers are items on an ORCID record that have been validated by an ORCID member organization rather than entered and self-reported by the record holder alone. ORCID currently recognizes several established categories of Trust Marker: validated affiliations added by universities and research institutions, validated funding awards added by funders, validated works added by publishers, and — added more recently — verified institutional email domains. In every case, the common thread is the same: the data did not simply come from the researcher typing it into a form. It was asserted, and is vouched for, by an organization with an ORCID membership agreement and a direct integration to the ORCID Registry.

On the public record, items carrying a Trust Marker are visually distinguished from self-asserted entries — typically shown with the source organization’s name and, where applicable, its logo, so a viewer can see at a glance which organization is standing behind that specific piece of data.

Trust Markers vs. Self-Asserted Data

Self-asserted data is anything a researcher enters directly into their own ORCID record: typing in a past employer, adding a qualification, or pasting in a list of publications. ORCID has always supported this, and it remains the majority of what most records contain, since not every institution or funder has a live ORCID integration.

Institution-asserted data is different in three respects that matter for downstream trust:

  • Provenance is explicit. The record shows which organization added the item, not just that “someone” added it.
  • It requires a membership relationship. Only organizations with an ORCID membership agreement — not arbitrary third parties — can write institution-asserted data to a record, and only with the researcher’s permission.
  • It is generally harder to falsify. A self-asserted employment claim can be typed in by anyone with access to the account; an institution-asserted one had to pass through that institution’s own HR, registrar, or research-office data and its ORCID integration before landing on the record.

This distinction is why Trust Markers exist as a concept at all: ORCID’s data model has always allowed the researcher to say almost anything about themselves, and Trust Markers give downstream consumers — a funder checking a grant application, a CRIS ingesting affiliation data, a publisher validating an author’s institution — a way to tell which claims carry independent institutional backing.

How Institution-Asserted Affiliations Work

Institution-asserted affiliations are written to ORCID records through the ORCID Member API, the programmatic interface available to organizations with an ORCID membership. The affiliation sections of the API (Employment, Education, Distinction, Invited Position, Membership, Qualification, and Service, as of API version 3.0 and later) support standard create/update/delete operations, so an institutional system — typically an HR system, student information system, or CRIS — can add, update, or remove affiliation entries on a researcher’s record programmatically.

Two mechanics make this workable at institutional scale:

  • Consent first. An institution cannot write to a researcher’s record without that researcher first granting permission through ORCID’s OAuth flow (a three-legged OAuth token with the /activities/update scope). ORCID’s identity model is explicitly researcher-controlled: institutions push data only into records that have authorized them to do so.
  • Affiliation Manager for non-developers. Institutions that don’t want to build a custom API integration can use ORCID’s Affiliation Manager, a tool that accepts a CSV upload of researcher affiliation data (employment, education, qualifications, invited positions, distinctions, memberships, and service) and, once approved, writes it to each researcher’s record automatically — the same institution-asserted result as a full API integration, without custom development work.

Once written, each affiliation entry carries a “put code” — a short reference ID used to update or remove that specific entry later — and displays the asserting organization’s name on the public record, which is what makes it recognizable as institution-asserted rather than self-entered.

Verified Institutional Email Domains

Verified email domains are a newer, narrower Trust Marker, rolled out by ORCID in September 2024. Rather than asserting a full affiliation record, this feature lets a researcher demonstrate an institutional association using only the domain portion of their institutional email address — the part after the “@” — without exposing their full email address publicly.

The mechanics, per ORCID’s own documentation:

  • A researcher verifies an institutional email address (e.g., an address ending in a university’s domain) through ORCID’s standard email-verification flow.
  • ORCID maps that domain to the correct organization using the domain information already present in the Research Organization Registry (ROR) — the same open, community-governed registry CASRAI covers elsewhere as the standard identifier for research organizations.
  • Once mapped, the verified domain becomes a Trust Marker on the record: visible proof of institutional association tied to a specific, ROR-identified organization, without requiring the researcher to publish their complete email address.

ORCID has reported that privacy concerns previously kept full email-address visibility low — fewer than 5% of researchers made a complete institutional email address public on their record — while domain-only verification is designed to remove that barrier. As of ORCID’s own reporting, roughly 2.9 million active ORCID records carry at least one verified institutional email domain usable as a Trust Marker.

Because the domain is matched against ROR, this Trust Marker is also inherently machine-actionable: a system consuming ORCID records can programmatically check whether a given record’s verified domain resolves to a specific institution’s ROR ID, without any manual review.

Why This Matters for Institutional Research Visibility

For research administrators, CRIS managers, and institutional repository teams, Trust Markers change what an ORCID-derived affiliation claim is worth as evidence:

  • Harvesting and disambiguation. A CRIS or research-information system that ingests ORCID data for institutional reporting can prioritize or flag institution-asserted affiliations and verified email domains differently from self-asserted claims, reducing false positives when disambiguating “who currently belongs to this institution.”
  • Funder and publisher reporting. Where a funder or publisher workflow checks a researcher’s institutional affiliation against an ORCID record, an institution-asserted entry (or a verified domain tied to that institution’s ROR ID) is stronger evidence than a self-reported affiliation the researcher could enter for any institution regardless of actual employment status.
  • Research visibility and attribution. Institutions have an incentive to push affiliation data to their researchers’ ORCID records precisely because Trust-Marked affiliations make institutional attribution more reliable across the wider scholarly infrastructure — citation databases, repositories, and funder systems that pull affiliation data from ORCID inherit that added reliability.
  • Reduced maintenance burden on researchers. Because institution-asserted data is pushed automatically (via API integration or Affiliation Manager CSV upload) rather than requiring the researcher to keep their own record current, it also tends to be more current, which matters for time-sensitive uses like verifying current affiliation on a live grant application.

None of this makes self-asserted data untrustworthy by default — most ORCID records still rely heavily on it, and ORCID’s own model treats self-assertion as legitimate. Trust Markers instead add a second, independently-verifiable layer on top, which is what CRIS and research-information workflows increasingly rely on when the stakes of getting an affiliation claim wrong (compliance, funder reporting, authorship disputes) are higher than a casual profile lookup.

What Institutions Need to Do

To assert affiliations or otherwise contribute Trust-Marked data, an organization needs an ORCID membership (via ORCID’s institutional or consortium membership programs) and either a custom integration against the Member API or use of the no-code Affiliation Manager CSV tool. Verified email domains, by contrast, don’t require any action from the institution itself beyond having accurate domain information registered in ROR — the verification step is something the individual researcher does on their own ORCID account.

What Researchers See on Their Own Record

From the researcher’s side, Trust-Marked entries appear alongside self-asserted ones but are labeled with the asserting organization, and researchers retain ORCID’s standard granular visibility controls (public, trusted-organization, or private) over each item, including Trust-Marked ones — an institution asserting data to a record does not remove the researcher’s control over who can see it.

Frequently Asked Questions

Can a researcher remove or edit an institution-asserted affiliation?

A researcher cannot directly edit data another organization asserted, since that organization is the source of record for that entry, but researchers control its visibility and can typically request removal by contacting the asserting institution, which then updates or deletes the entry via the same API access it used to add it.

Is a verified email domain the same as making an email address public?

No. The verified email domain Trust Marker exposes only the domain (the part after the “@”), matched to an organization via ROR — not the researcher’s actual email address, which stays private unless the researcher separately chooses to publish it.

Do all ORCID member organizations automatically get Trust Marker capability?

Writing institution-asserted affiliations requires an active ORCID membership and either a Member API integration or use of the Affiliation Manager tool — it is not available to organizations without a membership agreement, and always requires the individual researcher’s consent before data is written to their record.

How does this relate to a CRIS or research-information system?

A CRIS that ingests ORCID data as part of institutional research-information management can use the presence of a Trust Marker as a signal of data reliability when reconciling affiliation records, funding data, or publication lists pulled from ORCID against internal institutional records.

Related CASRAI Resources

Sources

  • ORCID, “Trust Markers in ORCID Records: Verified Email Domains,” info.orcid.org.
  • ORCID Support, “Add a verified institutional email domain to your record,” support.orcid.org.
  • ORCID-Source API documentation and tutorial, “Affiliations,” github.com/ORCID/ORCID-Source.
  • Research Organization Registry (ROR), ror.org.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →