It was built to directly mitigate events like the Latitude breach whereby the service gives an answer to an identity question rather than spraying PII across the economy. Answers were formed by pulling data from disparate authoritative sources in real time, a set of tokens were created and an audit record created and shared with PII owner consent. No personal information was ever intended to be shared or stored. It was an elegant solution for New Zealand, though we were mindful of a potential scaling issues in larger jurisdictions.
The financial sector was the initial target to help with AML/KYC flows. The banks in particular lobbied for access to the PII rather than an answer to the question so the service was devalued from the get go. If we’d won that answer I believe that digital identity and personal information sharing would be very different today.