Identity sovereignty
Identity sovereignty.
Identity sovereignty means your organisation holds authority over its identities, their access and their sign-in. Who belongs, who may do what and who signs in where is decided by you, in your systems, without a directory or cloud vendor having a say. Warpbeam is the warp beam for that: the threads, meaning your identities, stay in your hands.
StatusToday Warpbeam works with your existing directory. The path to full identity sovereignty is decided and specified; building it is still ahead.
Who holds the threads?
Your fabric. Your loom.
Five questions that measure identity sovereignty, and how Warpbeam is meant to answer them when run sovereign.
- Where is an identity created and kept?
- In Warpbeam, on your premises.
- Who checks passwords and passkeys?
- Warpbeam.
- Who signs users in to applications?
- Warpbeam, using open standards.
- Who rolls out policies to servers and workstations?
- Warpbeam, through an agent on each device.
- Where do the keys live?
- With you: in your hardware security module if you have one, otherwise in Warpbeam's built-in key store.
Operating modes
Three operating modes.
With your directory
Warpbeam governs; your existing directory holds the accounts.
Usable todaySide by side
Warpbeam takes the lead step by step. The old directory becomes a target that Warpbeam feeds, until it has nothing left to do.
Target stateSovereign
Warpbeam is directory, sign-in service and policy engine. Servers and workstations no longer need to join a domain.
Target state
An exit assistant is meant to guide you from 1 to 3. At every point it shows what still depends on the old directory, say “37 servers and 4 applications left” (example). Every step can be undone. If you want to keep your directory, keep it.
For the move itself, there is to be a migration tool, offered only as a service from Germany: it moves identities, access rights, mailboxes and files between directories, from on-premises systems to the cloud, between cloud tenants, and into a sovereign environment built on open software. If you run Warpbeam yourself, you get a time-limited tenant for this.
Not to be confused
Not the same as SSI.
Self-sovereign identity usually means an individual's authority over their own digital identity, for example with a digital wallet and verifiable credentials.
Warpbeam means the organisation's authority over every identity that works for it. The two don't exclude each other: credentials from a digital wallet could later serve as evidence when new identities are onboarded. That's a long-term goal, not part of Warpbeam today.
Open standards
Open standards, not a clone.
Warpbeam doesn't rebuild someone else's directory. Applications talk to Warpbeam over widely used open protocols for directory lookups, sign-in and account provisioning. On each device, a small agent handles sign-in, local accounts and policies.
Duties
Sovereignty means responsibility.
Run sovereign, and Warpbeam becomes the most critical system you own. That means well-protected keys, ideally in a security module, high-availability operation, an emergency login on every device that works without Warpbeam, and a small, hardened attack surface.
We say this up front, because sovereignty without these duties would be a promise without cover.
AI
Your AI stays with you, too.
The language model is to run inside Warpbeam itself: an open model as a signed data package, with no connection to the internet. If you run Warpbeam yourself, it runs with you. A model of your own, in your data centre or with a provider you choose, can be connected in addition. Without a model, Warpbeam keeps working in full. Your data never trains a model.