Skip to content
warpbeam

Identity sovereignty

Identity sovereignty.

Identity sovereignty means your organisation holds authority over its identities, their access and their sign-in. Who belongs, who may do what and who signs in where is decided by you, in your systems, without a directory or cloud vendor having a say. Warpbeam is the warp beam for that: the threads, meaning your identities, stay in your hands.

StatusToday Warpbeam works with your existing directory. The path to full identity sovereignty is decided and specified; building it is still ahead.

Who holds the threads?

Your fabric. Your loom.

Five questions that measure identity sovereignty, and how Warpbeam is meant to answer them when run sovereign.

Where is an identity created and kept?
In Warpbeam, on your premises.
Who checks passwords and passkeys?
Warpbeam.
Who signs users in to applications?
Warpbeam, using open standards.
Who rolls out policies to servers and workstations?
Warpbeam, through an agent on each device.
Where do the keys live?
With you: in your hardware security module if you have one, otherwise in Warpbeam's built-in key store.

Operating modes

Three operating modes.

  1. With your directory

    Warpbeam governs; your existing directory holds the accounts.

    Usable today
  2. Side by side

    Warpbeam takes the lead step by step. The old directory becomes a target that Warpbeam feeds, until it has nothing left to do.

    Target state
  3. Sovereign

    Warpbeam is directory, sign-in service and policy engine. Servers and workstations no longer need to join a domain.

    Target state

An exit assistant is meant to guide you from 1 to 3. At every point it shows what still depends on the old directory, say “37 servers and 4 applications left” (example). Every step can be undone. If you want to keep your directory, keep it.

For the move itself, there is to be a migration tool, offered only as a service from Germany: it moves identities, access rights, mailboxes and files between directories, from on-premises systems to the cloud, between cloud tenants, and into a sovereign environment built on open software. If you run Warpbeam yourself, you get a time-limited tenant for this.

Not to be confused

Not the same as SSI.

Self-sovereign identity usually means an individual's authority over their own digital identity, for example with a digital wallet and verifiable credentials.

Warpbeam means the organisation's authority over every identity that works for it. The two don't exclude each other: credentials from a digital wallet could later serve as evidence when new identities are onboarded. That's a long-term goal, not part of Warpbeam today.

Open standards

Open standards, not a clone.

Warpbeam doesn't rebuild someone else's directory. Applications talk to Warpbeam over widely used open protocols for directory lookups, sign-in and account provisioning. On each device, a small agent handles sign-in, local accounts and policies.

Duties

Sovereignty means responsibility.

Run sovereign, and Warpbeam becomes the most critical system you own. That means well-protected keys, ideally in a security module, high-availability operation, an emergency login on every device that works without Warpbeam, and a small, hardened attack surface.

We say this up front, because sovereignty without these duties would be a promise without cover.

AI

Your AI stays with you, too.

The language model is to run inside Warpbeam itself: an open model as a signed data package, with no connection to the internet. If you run Warpbeam yourself, it runs with you. A model of your own, in your data centre or with a provider you choose, can be connected in addition. Without a model, Warpbeam keeps working in full. Your data never trains a model.