Introduction
Governments no longer operate in neatly differentiated silos of the public and private sectors. Advances in technology, specialised expertise, and the changing nature of public administration increasingly require governments to work with private actors. India is no exception. Consultants, third-party vendors, outsourcing agencies, and technology providers now work with ministries and departments on a day-to-day basis. At the same time, millions of public servants perform functions that require access to government information and systems.
Many of these individuals have access to data that may be sensitive, confidential, or otherwise consequential if disclosed. Unauthorised disclosures of such information are not uncommon.
At best, ministries and departments may rely on a NDA, contractual confidentiality provisions, or the Official Secrets Act (OSA). Yet these mechanisms primarily address the consequences of unauthorised disclosure. They do little to answer a more fundamental question: how should the government assess the risk posed by an individual before granting them access to sensitive information?
One might point to police verification, character certificates, or antecedent reports as existing safeguards. But these mechanisms largely establish what is already known about an individual at a particular point in time. They do not provide a framework for assessing whether that individual is suitable for access to particular categories of sensitive information. Nor do they ordinarily provide for the continuous evaluation of that suitability once access has been granted.
This raises a broader question of personnel security: should access to sensitive government information depend solely on an individual’s status at a given time, or should it also include a structured & continuous assessment of the risks which can alert the government before a leak?
The Model
The answer is not to outright ban or restrict these individuals or organisations. Rather, access to sensitive government information could be made conditional on an appropriate level of trust, determined through a standardised vetting mechanism.
This is not a novel concept. The United States and the United Kingdom already operate structured personnel-security and security-clearance systems that assess individuals before granting access and, increasingly, continue to assess their suitability thereafter.
In the United States, individuals requiring access to classified information are subject to different levels of security clearance, broadly corresponding to Confidential, Secret, and Top Secret. The process is standardised, and individuals who receive clearance may remain subject to continuing evaluation. The entire process is standardised, online, and largely time-bound. Even those who receive clearance may remain subject to continuous evaluation, and identified security concerns may result in their clearance being downgraded, suspended, or revoked.
The United Kingdom has a similarly structured and tiered national-security vetting framework.
For India, we need not replicate the entire process ut totum. Rather, we can look at the core principles, best practices, and the working framework to adopt suitably for our needs and context.
A standardised clearance system in India could be recognised across government. This would reduce the need to repeatedly establish an individual’s suitability each time they move between departments or assignments, while still allowing departments to impose additional requirements where the sensitivity of the role warrants it.
Benefits
A standardised personnel-security framework would provide benefits at several levels.
First, uniformity. A common framework would give government departments a shared understanding of what level of trust is required for different categories of information, roles and positions, and who may be granted access to them. This would reduce the dependence on department-specific practices and create greater consistency and understanding across government.
Second, portability of trust. For departments, a formal clearance would provide a commonly recognised layer of trust. For individuals, it could allow them to move between departments or assignments without having to repeatedly establish their suitability from scratch, subject to the requirements of their new role.
Third, course correction. A structured system creates an institutional mechanism for learning from single and isolated security failures. After a breach, the question is not merely whether an individual failed, but whether the vetting, access controls, or continuing-evaluation mechanisms failed to identify or mitigate the relevant risk. Lessons from one incident can therefore be incorporated into the wider framework and applied across government, rather than remaining confined to the affected department.
The 2023 U.S. Air National Guard Discord leak provides an illustration of this principle. The incident prompted renewed scrutiny of how classified information was accessed and handled, and of the safeguards surrounding personnel with access to such information. A centralised and continuously evolving framework that learns lessons from such incidents can inform safeguards beyond the organisation directly affected, strengthening the system as a whole.
The larger opportunity, therefore, is to move from a system that primarily responds to breaches to one that anticipates and smartly manages personnel risk. The question now, therefore, is what an Indian version of it could look like.
Roadmap for India
In India, if such a mechanism is to be introduced, a national nodal agency, perhaps under MHA, shall have to assume authority. We already have enough sources of real-time information through digitised police, financial, judicial, immigration and other records. The challenge is therefore not the absence of information, but the fragmented nature of information across institutions and levels of government. A personnel-security system would need to allow these disparate sources to communicate through a common, secure, and permissioned architecture, while ensuring that information is accessed only for authorised purposes. This makes a Digital Public Infrastructure (DPI) approach particularly relevant. Rather than creating another standalone database or portal, the system could provide common digital rails through which existing government systems can securely exchange relevant information. The objective would be to make existing systems interoperable while retaining appropriate authentication, access controls, and audit trails, without the need to consolidate or centralise underlying data and mechanisms.
Here is a suggestive flow of a solution that I am tentatively calling e-NETRA (electronic Networked Evaluation of Trust and Realtime Assessment):
The diagram illustrates the basic layers of a DPI architecture, alongside examples of how those layers could operate within e-NETRA.
At a practical level, e-NETRA could connect to information sources ranging from sub-district administrations, police stations, and lower courts to national-level systems such as immigration, PAN, and bank databases. Rather than requiring each department to independently collect and verify the same information, the system could retrieve relevant information from these sources within milliseconds through APIs, at defined intervals or when a specific trigger requires review. Potential concerns identified through these checks could then be flagged for automatic or human review followed by appropriate action.
The following diagram provides a simplified illustration of how e-NETRA could process a new clearance request:
This workflow ensures:
- Standardised screening: Every clearance request follows a common process rather than disparate verification practices.
- Multiple data sources: The system can draw relevant information from authorised police, district administration, financial, judicial, intelligence, and other government sources.
- Lifecycle approach: Clearance is not treated as a one-time certificate. The same record can feed into the subsequent continuous-evaluation process.
- Audit trail: Clearance requests, decisions, rejections, and subsequent actions can be recorded, creating an auditable history of the clearance process.
This is, deliberately, a rudimentary and illustrative workflow. The important principle is that the initial clearance decision would not necessarily be the end of the process. Once an individual or organisation has been granted security clearance, e-NETRA could continue evaluating relevant information and flag potential anomalies or security concerns for review, as illustrated below.
Once clearance is granted, the entity enters continuous evaluation. e-NETRA periodically checks data sources for new information or potential concerns. Where a concern is detected, it is flagged for review. The initial review could be automated using machine-learning models or, where necessary, referred for manual review. The review may result in no change or, where warranted, downgrading or removal of the clearance, with the decision recorded in the audit log and registry.
This proposed architecture could make personnel security more standardised, interoperable, and proactive. But the same architecture would also bring together significant amounts of information and give the State greater capacity to evaluate individuals on a regular basis. Therefore, it becomes equally important to discuss the governance of such a system.
Governance
Some key principles of governance could include:
- Secure by design: Data handled by e-NETRA should be encrypted both in transit and at rest, with strong authentication and role-based access controls governing access to the system and underlying information.
- Data minimisation: The system should access only information relevant to the clearance being assessed.
- Human oversight: Automated flags or machine-learning assessments should not, by themselves, result in permanent suspension, downgrading, or removal of a clearance. Significant changes should be human reviewed.
- Blind Human Review: Human reviewers should not see an individual’s identifying information or other unnecessary PII while reviewing a flagged case. They should only see the information necessary to assess the specific concern, reducing the scope for bias, undue influence, or corruption.
- Natural justice: Individuals should have an opportunity to know and respond to adverse information relied upon in making a decision. The principles of the right to be heard and natural justice should be followed.
- Appeal and redress: An appropriate mechanism should allow individuals to challenge adverse decisions or incorrect information. At the same time, safeguards should prevent frivolous or repetitive appeals from unnecessarily clogging the system.
- Protection for good-faith disclosure: Information voluntarily disclosed for the purpose of personnel-security vetting should not, by itself, trigger punitive or criminal action against the individual, particularly in non-cognizable petty matters.
- Cost allocation: The cost of vetting should ordinarily be borne by the employer. The government department or third-party vendor/agency seeking clearance, rather than by the individual being vetted.
- U.S. Defense Counterintelligence and Security Agency (DCSA). (2026). Continuous Vetting. Washington, D.C.
- Cabinet Office, Government of the United Kingdom. (2024). National Security Vetting: Clearance Levels. London.
- The Indian Express. (2023). TSPSC paper leak: Outsourced employee allegedly accessed confidential question papers using other employees’ credentials. Hyderabad.
- Times of India. (2023). Defence data leak likely through Delhi agencies hired by MoD. Hyderabad.
- Times of India. (2023). Leaking of defence info: CSL worker sent to police custody. Kochi.
- Hindustan Times. (2024). ATS arrests Navi Mumbai man for sharing “sensitive” info with Pakistani spy. Mumbai.
- The New Indian Express. (2025). NIA arrests Kochi man in espionage case. Kochi.