HIF / Documentation / Identity systems

Brand Expression

Status: normative foundation and governance reference

Version: 0.1

This document defines how identity may be expressed through an HIF-conforming interface without changing the truth, semantics, accessibility or agency of the product. It supports a single product, a family of products, white-label delivery and independently governed brands.

1. Brand is not the interface contract

HIF distinguishes:

  • identity: who is speaking or responsible;
  • reputation: beliefs formed through experience and communication;
  • promise: the expectations an organisation deliberately creates;
  • expression: perceptible assets and behaviours used to identify the organisation or product;
  • trade mark: a sign whose use and protection depend on jurisdiction, registration, class and context;
  • product semantics: objects, commands, states, consequences and permissions;
  • platform convention: behaviour people rely on in an environment.

Brand MAY influence expression. It MUST NOT redefine:

  • whether an action is primary, destructive or reversible;
  • whether data are saved, shared, deleted or charged for;
  • the meaning of success, warning, danger or disabled;
  • native accessibility semantics;
  • platform-owned security or permission surfaces;
  • the prominence required for material terms;
  • the ability to refuse, cancel, recover or contact support.

Visual consistency cannot compensate for a broken promise. The most durable brand expression is accurate, reliable product behaviour.

2. Brand strategy record

Before designing assets, record:

BRAND-ID and owner
legal entity and accountable product
audiences and contexts
promise and evidence supporting it
positioning and genuine points of difference
recognition assets and their present strength
portfolio relationship
names, domains and marks
voice and language policy
experience principles
prohibited implications
accessibility and cultural constraints
jurisdictions and legal review
measurement and review date

“Premium”, “human”, “innovative”, “simple”, “bold” and similar adjectives are not design specifications. Each attribute MUST be translated into observable behaviour, bounded expression rules and counterexamples.

3. Distinctiveness and recognition

Distinctiveness is the ability to identify the source without requiring a persuasive claim. Differentiation is a substantive perceived difference. They are related but not interchangeable.

A candidate asset SHOULD be evaluated for:

  • uniqueness: association with one source rather than the category;
  • fame: proportion of the intended audience that recognises it;
  • fluency: speed and confidence of correct recognition;
  • reach: recognition across relevant languages, abilities and contexts;
  • flexibility: survival at required sizes, media and modes;
  • protectability: legal availability and enforceability where required;
  • provenance: documented authorship, licence and permitted uses;
  • confusability: risk of confusion with another entity, status or control.

Recognition MUST be measured without coaching people with the brand name in the question. A mood-board resemblance or internal preference vote is not evidence of public distinctiveness.

The system SHOULD cultivate a small coherent set of recognition assets rather than changing every variable. Consistency is valuable only while the assets remain truthful, accessible and legally usable.

4. Expression system

4.1 Asset classes

The brand registry MAY include:

  • legal and product names;
  • wordmarks, symbols and signatures;
  • colour and colour combinations;
  • typography;
  • shape, framing and layout motifs;
  • iconographic and illustration style;
  • photographic direction;
  • motion, transition and spatial behaviour;
  • sound marks, earcons and voice;
  • haptic signatures;
  • language, vocabulary and narrative;
  • physical materials and environmental expression;
  • data-visualisation accent and publication style.

Every asset MUST have a defined purpose and non-purpose. A logo identifies; it does not establish that a payment is safe. A brand sound identifies; it does not replace an alarm.

4.2 Asset record

ASSET-ID and version
asset class and semantic purpose
source files and canonical checksum
creator and approval
copyright, trade-mark and patent status
licence, territory, duration and attribution
permitted products, media and modifications
minimum/maximum size and exclusion zone
colour-space, gamut and print specifications
light, dark, forced-colour and monochrome variants
accessible name or alternative
localisation and cultural review
deprecated and replacement versions

Files MUST NOT enter a production library as anonymous downloads. “Free”, “royalty-free” and “found online” do not define redistribution rights.

5. Identity and semantic colour

Brand colour and interface semantics are separate token domains:

brand primitive
→ brand expression role

system primitive
→ semantic interface role
→ component role

A brand accent MAY map to action.primary only if every required state and contrast constraint passes. Danger MUST NOT be mapped to a brand colour merely for visual consistency. Conversely, a brand red MUST NOT make ordinary brand decoration look like an error.

Define collision tests for:

  • brand versus danger, warning, success and information;
  • brand decoration versus links and focus;
  • logo versus security/trust indicators;
  • campaign treatments versus disabled or selected state;
  • partner colours versus product ownership.

Accessibility remediation MAY change an expression value without changing the source brand asset. The accessible mapping takes precedence in the interface.

6. Typography and brand

A distinctive typeface MAY support recognition, but the typography system MUST first support:

  • all required scripts and language features;
  • readable UI and long-form text at rendered sizes;
  • zoom, text spacing and reflow;
  • sufficient designed weights and styles;
  • unambiguous critical characters;
  • reliable fallback;
  • performance and privacy budgets;
  • application, embedding, redistribution and server-use rights.

Display typography SHOULD NOT be imposed on dense data, code, user-generated content or extended reading when it reduces task performance. Faux bold, synthetic italics and missing glyph fallback MUST be reviewed against the identity and legibility contract.

Font licensing MUST record files, versions, foundry/source, licence text, permitted channels, seat/page-view/application terms where applicable, subsetting/modification rights and attribution. A font name in a design file is not licence evidence.

7. Voice, tone and content identity

7.1 Voice

Voice is the stable language behaviour of the responsible organisation. Define:

  • relationship to the reader;
  • vocabulary and canonical object/command names;
  • sentence and information-order policy;
  • degree of formality;
  • use of first and second person;
  • treatment of uncertainty and evidence;
  • language, translation and transliteration policy;
  • prohibited claims, stereotypes and rhetorical devices.

Voice MUST preserve the domain vocabulary. Stylistic variation MUST NOT rename the same object or command in ways that obscure identity.

7.2 Tone

Tone varies with situation and consequence. A tone matrix SHOULD cover:

SituationRequired qualityProhibited tendency
Routine successconcise, factualcelebration that interrupts work
Delay or outagecandid, time-specificfalse reassurance
User errorconstructive, recoverableblame or ridicule
Product failureaccountable, actionabletransferring responsibility
Danger or lossdirect, calm, explicitjokes, euphemism or brand slogans
Consent or purchasebalanced, completepressure or asymmetric framing
Sensitive eventrespectful, privateperformative familiarity

Tone MUST NOT reduce disclosure, precision or the prominence of a material consequence.

7.3 Localisation

The canonical meaning precedes local expression. Localisation MAY adapt idiom, examples, reading direction and cultural reference, but MUST preserve object, command, state, consequence, uncertainty and legal meaning.

A local market team MUST NOT independently change identity ownership, consent semantics or status vocabulary. Transcreation requires a source-to-target decision record and native-speaker review in context.

8. Imagery, illustration, iconography and motion

Brand imagery MUST NOT:

  • imitate controls or system messages;
  • imply a product state or capability that does not exist;
  • represent excluded groups as a token gesture;
  • use a person's likeness or generated identity without documented authority;
  • obscure content or required focus/contrast;
  • normalise unsafe or unlawful behaviour;
  • conceal sponsorship, simulation or material editing.

An illustration and icon system MUST document grid, stroke/fill logic, optical correction, perspective, corner policy, sizes and accessible alternatives. Style MUST NOT override recognisability of common commands.

Motion MAY express continuity and identity, but MUST be interruptible, performance-bounded and compatible with reduced-motion preferences. A brand transition MUST NOT delay access to content, completion, cancellation or error recovery.

Sound and haptic identity MUST remain distinguishable from alerts, alarms, confirmation and assistive-technology output. System mute and user preferences take precedence.

9. White-label architecture

9.1 Definition

A white-label product has one maintained semantic and behavioural core with controlled identity mappings for authorised tenants or distributors. It is not a collection of forks whose appearance happens to differ.

Architecture:

HIF obligations
→ product/domain semantics
→ platform and component contracts
→ semantic tokens
→ brand-expression adapter
→ approved brand package

Lower layers MUST NOT override obligations above them.

9.2 Brand package

Each brand package MUST declare:

brand identifier and version
parent/portfolio relation
asset registry references
expression-token mappings
light/dark/contrast/forced-colour variants
typography and fallbacks
voice/content layer
domains, manifests and metadata
email, document, print and support identities
licences and expiry dates
compatibility range with the core product
test evidence and approvers

Runtime tenant values MUST be validated against a schema and allowlist. Raw CSS, HTML, executable templates, arbitrary URLs and unchecked font files MUST NOT be accepted as “branding”.

9.3 Non-customisable core

The following are non-customisable except through an approved core change:

  • accessible names, roles, values and state;
  • command meaning and order where safety depends on it;
  • destructive, financial, privacy and consent consequences;
  • focus and keyboard model;
  • validation and recovery logic;
  • security origin and accountable entity disclosure;
  • user contrast, motion, font and platform preferences;
  • audit, provenance and support routes required by policy or law.

9.4 Isolation

Brand packages MUST be isolated by tenant and environment. Cache keys, asset paths, generated metadata and server rendering MUST include the resolved brand identity. A request MUST NOT receive another tenant's logo, domain, support address, analytics or legal terms during failure or cache reuse.

Safe fallback is the verified neutral/core identity, not the last successfully loaded tenant.

10. Multi-brand portfolio governance

10.1 Portfolio model

Record whether the relationship is:

  • master brand;
  • endorsed brand;
  • sub-brand;
  • independent house of brands;
  • partner/co-brand;
  • temporary campaign;
  • neutral white-label.

The relationship determines naming, signature, attribution and responsibility. It MUST NOT be inferred from logo size alone.

10.2 Decision rights

Assign:

  • accountable brand owner;
  • product and semantic owner;
  • design-system owner;
  • accessibility and inclusive-design authority;
  • content/localisation authority;
  • legal/trade-mark and licensing review;
  • security and domain-identity owner;
  • tenant or partner approver;
  • final decision maker and incident owner.

Accessibility, truthful disclosure and platform security have veto authority over expression. Brand owners MAY choose an alternative conforming expression; they MAY NOT waive the obligation.

10.3 Change and release

Every material brand change MUST state:

  • reason and intended recognition effect;
  • affected brands, products and jurisdictions;
  • token and asset diffs;
  • semantic collision assessment;
  • accessibility evidence;
  • migration and compatibility;
  • cached/offline/transactional artefact handling;
  • measurement plan;
  • rollback and expiry.

A rename or ownership change is a system migration affecting domains, certificates, application manifests, stores, notifications, email, documents, support, legal notices, analytics and saved links—not a logo replacement.

11. Licensing, rights and provenance

11.1 Rights ledger

Maintain a rights ledger for every externally sourced or commissioned:

  • name and mark;
  • font;
  • icon, image and illustration;
  • audio, voice and haptic asset;
  • template and code;
  • palette or dataset;
  • model-generated asset and its inputs where relevant.

Record:

asset identity and checksum
author, supplier and commissioning entity
source URL/repository and acquisition date
declared and concluded licence
copyright and trade-mark owner
territory, channel, duration and audience
modification, sub-licensing and redistribution rights
attribution and notice
model/property/person releases
expiry, review and takedown route

SPDX identifiers SHOULD be used where the licence is in the SPDX list. Unknown rights MUST be represented as unknown, not inferred as permission.

11.2 Provenance

Provenance MUST survive:

  • format conversion and optimisation;
  • design-tool export;
  • token generation;
  • repository and package publication;
  • content-delivery transformation;
  • localisation and derivative creation;
  • retirement.

Use stable identifiers and checksums. C2PA content credentials MAY supplement the internal record for supported media, but absence of a credential neither proves nor disproves authenticity.

11.3 Trade marks

Trade-mark clearance, registration and correct use require qualified review in relevant jurisdictions. HIF does not determine legal availability. The system MUST record approved spelling, grammar, ownership marks, prohibited alterations, attribution and third-party use conditions.

12. Ethics, autonomy and dark patterns

Brand expression MUST NOT be used to subvert free and informed choice. Prohibit:

  • visual interference favouring consent, purchase or data disclosure;
  • false hierarchy between equivalent accept/refuse choices;
  • disguised advertising or sponsorship;
  • false scarcity, countdowns or social proof;
  • hidden material terms, fees or renewal;
  • confirm-shaming and blame;
  • obstruction of cancellation, deletion, refund or complaint;
  • repeated prompts after a durable refusal without a material change;
  • emotional imagery used to suppress risk comprehension;
  • imitation of official, security or independent certification signals;
  • personalisation designed to exploit a known vulnerability.

Conversion improvement does not justify impaired agency. Experiments MUST include harm and cancellation measures and MUST NOT randomise people into a design already known to be deceptive or unlawful.

13. Measurement

Balance recognition and business outcomes with human outcomes:

13.1 Recognition

  • unaided and aided recognition;
  • correct source attribution;
  • confusion with competitors, partners or system states;
  • recognition across size, mode, language and disability;
  • asset fame and uniqueness over time.

13.2 Experience

  • task success, error and recovery;
  • comprehension of ownership and consequence;
  • accessibility barriers;
  • trust calibration against actual reliability;
  • refusal, cancellation and support success;
  • complaints and identity/security incidents.

13.3 System health

  • unlicensed or expiring assets;
  • unknown provenance;
  • cross-tenant leakage;
  • nonconforming token overrides;
  • outdated transactional material;
  • design/code/content drift;
  • local exceptions and time to resolve.

Preference, conversion or spontaneous adjectives MUST NOT be the sole measure of brand-system quality.

14. Review protocol

14.1 Strategy

  • Accountable entity, audience, promise and evidence are stated.
  • Distinctiveness is separated from substantive differentiation.
  • Product semantics and platform conventions are protected.
  • Portfolio and co-brand relationships are explicit.
  • Prohibited implications and harms are defined.

14.2 Expression

  • Every asset has a purpose and non-purpose.
  • Recognition survives required sizes, media, modes and languages.
  • Brand and semantic colour collisions are tested.
  • Typography covers required scripts, accessibility and performance.
  • Voice and tone preserve object, command, state and consequence.
  • Imagery represents people and capability truthfully.
  • Motion, sound and haptics respect user preferences.

14.3 White-label engineering

  • The brand package conforms to schema and compatibility range.
  • Tenant input cannot inject arbitrary code or unapproved URLs.
  • Semantic and accessibility core is non-customisable.
  • Cache, metadata, domains, support and legal identity are isolated.
  • Neutral failure fallback is verified.
  • Screenshot, interaction and accessibility matrices pass for every released brand/mode combination.

14.4 Rights and ethics

  • Rights ledger and checksums are complete.
  • Trade-mark and jurisdiction review is recorded.
  • Attribution, expiry and takedown procedures are operational.
  • Consent, purchase, cancellation and deletion are visually balanced.
  • No brand treatment imitates state, authority or certification.
  • Accessibility overrides take precedence and remain recognisable.

14.5 Release

  • Owners and approvers signed the change record.
  • Assets, tokens, code, content and documentation share one version.
  • Offline, transactional, print and support surfaces are included.
  • Measurement includes confusion, harm and accessibility.
  • Rollback restores a complete, legally valid identity.

15. Sources

All sources are English-language original research, standards, legislation or official specifications. Retrieval date: 30 July 2026.