Roadmap
What runs. What's next.
The identity fabric is the cloth. Here you see how densely it is woven today: every capability, structured along a widely used reference model, each with a measured status. Plus the order in which we build, without promising dates.
Status23 September 2026, measured against the code. Maturity 0 missing, 1 foundation, 2 usable (the core flow runs in our test environment), 3 extensive, 4 complete. Coverage: share of planned functions that is built; partly built counts half. Today no capability is extensive or complete. Warpbeam is not yet for sale; this site provides information about the software.
Weave
How densely the fabric is woven today.
Every vertical line stands for a capability: the thicker, the further along it is today. Every phase is a row across; a knot shows which capabilities it moves forward. Pick a phase or a capability.
The assignment comes from our target picture; 2 capabilities are not assigned to a phase yet and show as “not scheduled yet”.
- Maturity 0 · missing dashed
- Maturity 1 · foundation thin
- Maturity 2 · usable medium
- Maturity 3 · extensive thick
- Maturity 4 · complete thickest
- Knot This phase moves the capability forward.
Pick a phase or a capability. The explanation appears below the picture; a second click or the Escape key closes it.
The graphic scrolls sideways. Everything is also listed below.
On narrow screens, only the phases are listed here. The table below shows every capability with its status.
Nothing selected yet.
Phases
-
Phase F: Build the foundation
Before further capabilities are added, the foundation comes first, built in five waves, each closed by a check gate: the hardened Linux server in containers with roles you can switch on, secure connections to the agents, separated tenants, high availability and performance, the AI foundation, the identity API, metrics and evidence. We close open items in what exists first. The Linux server form is in place before the first delivery to customers; running Warpbeam as a service follows as a milestone of its own.
Moves forward in the target picture: Secrets, Adaptive authentication, Dynamic authorization, Privilege elevation, Access governance, Access analytics, API security, Security events, Identity API, Orchestration, Performance, Resilience.
-
Phase A: Machines, interfaces, first AI
Machines fetch their own secrets, APIs get a gateway of their own, AI agents become identities with runtime control. First AI functions: explaining findings, proposing actions, today's tasks, plus the emergency stop, rollback and a first learning mode.
Moves forward in the target picture: Identity repository, Secrets, Dynamic authorization, Just-in-time access, API security, Relationships.
-
Phase B: Warpbeam as issuer
Warpbeam signs users in to applications with its own sign-in service over open standards, with keys in a security module or the built-in key store. Plus web applications behind our own web proxy with a web application firewall, and access to applications without a VPN. No language model in the sign-in path. For identity sovereignty: the core of a directory of its own.
Moves forward in the target picture: Federation, Web access management, Secure service edge.
-
Phase C: Governance at full breadth
Data access, review policies, ownership, segregation of duties, identity proofing. The AI recommends and explains; once it has passed learning mode, it may act on its own within limits. Widely used applications get connected. Sign-in to computers without a domain.
Moves forward in the target picture: Identity repository, Onboarding and proofing, Lifecycle, Provisioning, Roles and policies, Application risk, Access governance, Data access governance, IT service management, Relationships.
-
Phase D: Operational maturity
The remaining engines of our own: collecting and answering security events, the web gateway, the built-in AI runtime, server sessions with recording, and PDF reports. Plus events from the environment, IT service management, password self-service, our own certificate management with or without an existing Windows CA, device management with updates and software distribution, monitoring and backup, network access, compliance and data protection evidence, behaviour analytics, questions in plain language and a backup of your existing directory. And the migration tool, offered only as a service: moves between directories, mailboxes and file stores, including into a sovereign environment.
Moves forward in the target picture: Sessions, Access analytics, Behaviour analytics, Security events.
Capabilities
-
Identity repository
Maturity 2 · usable
Coverage 17 %: 8 of 142 planned functions built, 33 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase A, Phase C.
-
Onboarding and proofing
Maturity 1 · foundation
Coverage 3 %: 0 of 70 planned functions built, 4 partly.
Next step: get the core flow running end to end (usable). Phase: Phase C.
-
Lifecycle
Maturity 1 · foundation
Coverage 15 %: 2 of 102 planned functions built, 26 partly.
Next step: get the core flow running end to end (usable). Phase: Phase C.
-
Provisioning
Maturity 2 · usable
Coverage 17 %: 4 of 157 planned functions built, 44 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase C.
-
Secrets
Maturity 2 · usable
Coverage 14 %: 14 of 252 planned functions built, 41 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase A.
-
Federation
Maturity 1 · foundation
Coverage 5 %: 1 of 86 planned functions built, 6 partly.
Next step: get the core flow running end to end (usable). Phase: Phase B.
-
Adaptive authentication
Maturity 2 · usable
Coverage 29 %: 14 of 83 planned functions built, 20 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase F.
-
Strong and passwordless sign-in
Maturity 2 · usable
Coverage 13 %: 3 of 71 planned functions built, 13 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: not scheduled yet.
-
Sessions
Maturity 1 · foundation
Coverage 13 %: 3 of 63 planned functions built, 10 partly.
Next step: get the core flow running end to end (usable). Phase: Phase D.
-
Roles and policies
Maturity 2 · usable
Coverage 15 %: 4 of 110 planned functions built, 24 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase C.
-
Dynamic authorization
Maturity 2 · usable
Coverage 19 %: 2 of 43 planned functions built, 12 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase A.
-
Just-in-time access
Maturity 2 · usable
Coverage 18 %: 2 of 46 planned functions built, 13 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase A.
-
Privilege elevation
Maturity 1 · foundation
Coverage 25 %: 6 of 42 planned functions built, 9 partly.
Next step: get the core flow running end to end (usable). Phase: Phase F.
-
Web access management
Maturity 1 · foundation
Coverage 1 %: 0 of 35 planned functions built, 1 partly.
Next step: get the core flow running end to end (usable). Phase: Phase B.
-
Application risk
Maturity 1 · foundation
Coverage 9 %: 0 of 74 planned functions built, 14 partly.
Next step: get the core flow running end to end (usable). Phase: Phase C.
-
Access governance
Maturity 2 · usable
Coverage 12 %: 2 of 119 planned functions built, 24 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase C.
-
Access analytics
Maturity 2 · usable
Coverage 30 %: 4 of 46 planned functions built, 20 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase D.
-
Behaviour analytics
Maturity 2 · usable
Coverage 21 %: 2 of 53 planned functions built, 18 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase D.
-
API security
Maturity 2 · usable
Coverage 7 %: 2 of 106 planned functions built, 11 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase A.
-
Identity threat detection and response
Maturity 2 · usable
Coverage 19 %: 8 of 127 planned functions built, 31 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: not scheduled yet.
-
Data access governance
Maturity 0 · missing
Coverage 0 %: 0 of 62 planned functions built, 0 partly.
Next step: build first functions so the foundation stands. Phase: Phase C.
-
Security events
Maturity 2 · usable
Coverage 14 %: 3 of 64 planned functions built, 12 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase D.
-
IT service management
Maturity 1 · foundation
Coverage 3 %: 0 of 77 planned functions built, 5 partly.
Next step: get the core flow running end to end (usable). Phase: Phase C.
-
Secure service edge
Maturity 1 · foundation
Coverage 6 %: 0 of 71 planned functions built, 8 partly.
Next step: get the core flow running end to end (usable). Phase: Phase B.
-
Identity API
Maturity 2 · usable
Coverage 16 %: 5 of 58 planned functions built, 8 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase F.
-
Relationships
Maturity 1 · foundation
Coverage 16 %: 1 of 32 planned functions built, 8 partly.
Next step: get the core flow running end to end (usable). Phase: Phase A, Phase C.
-
Orchestration
Maturity 2 · usable
Coverage 9 %: 7 of 195 planned functions built, 23 partly.
Next step: raise coverage to at least three quarters (extensive). Phase: Phase F.
-
Performance
Maturity 1 · foundation
Coverage 3 %: 0 of 29 planned functions built, 2 partly.
Next step: get the core flow running end to end (usable). Phase: Phase F.
-
Resilience
Maturity 1 · foundation
Coverage 9 %: 1 of 101 planned functions built, 16 partly.
Next step: get the core flow running end to end (usable). Phase: Phase F.
Capabilities
Every capability at a glance.
Maturity 0 · missing 1 Maturity 1 · foundation 12 Maturity 2 · usable 16 Maturity 3 · extensive 0 Maturity 4 · complete 0 (29 measured capabilities; plus 5 cross-cutting items, not measured)
| Capability | Target: what it is meant to do for you | Status |
|---|---|---|
| Administration | ||
| Identity repository | Every identity in one place, with its origin and history. | Maturity 2 · usableCoverage 17 % |
| Onboarding and proofing | New identities are verified before they get any access. | Maturity 1 · foundationCoverage 3 % |
| Lifecycle | Joiners, movers and leavers take effect everywhere, driven from HR. | Maturity 1 · foundationCoverage 15 % |
| Provisioning | Accounts and access appear in target systems on their own, and disappear again. | Maturity 2 · usableCoverage 17 % |
| Secrets | Passwords and keys for people and machines live in a vault, not in scripts. Certificates are found, issued, deployed and renewed – with an own certificate authority, even without any directory service. | Maturity 2 · usableCoverage 14 % |
| Authentication | ||
| Federation | Applications are meant to sign users in over OIDC, OAuth and SAML, with Warpbeam's own sign-in service as the issuer. | Maturity 1 · foundationCoverage 5 % |
| Adaptive authentication | Risky sign-ins are spotted and held. | Maturity 2 · usableCoverage 29 % |
| Strong and passwordless sign-in | Multiple factors and passkeys instead of a password alone. | Maturity 2 · usableCoverage 13 % |
| Sessions | Active sessions can be seen and ended. Sessions on servers (RDP, SSH) are meant to run through an engine of our own, with recording. | Maturity 1 · foundationCoverage 13 % |
| Authorization | ||
| Roles and policies | Who may do what follows from roles and rules, not one-off exceptions. | Maturity 2 · usableCoverage 15 % |
| Dynamic authorization | Access takes the situation into account: device, location, risk. | Maturity 2 · usableCoverage 19 % |
| Just-in-time access | Admin rights exist only for as long as they are needed. | Maturity 2 · usableCoverage 18 % |
| Privilege elevation | Admins work with normal accounts and elevate only when needed. | Maturity 1 · foundationCoverage 25 % |
| Web access management | Web applications are meant to be protected by our own web proxy with its own web application firewall, even without a sign-in of their own. | Maturity 1 · foundationCoverage 1 % |
| Analytics and audit | ||
| Application risk | Risky combinations of rights inside applications are detected, for example segregation of duties. | Maturity 1 · foundationCoverage 9 % |
| Access governance | Owners confirm access regularly, with evidence. Risks, suppliers and your own controls are meant to live in one register, with evidence for auditors. | Maturity 2 · usableCoverage 12 % |
| Access analytics | Surplus and unusual access becomes visible. | Maturity 2 · usableCoverage 30 % |
| Behaviour analytics | Unusual account behaviour stands out. | Maturity 2 · usableCoverage 21 % |
| Extended | ||
| API security | Machines and tools get in only with their own, limited identity. | Maturity 2 · usableCoverage 7 % |
| Identity threat detection and response | Attacks on identities are detected; Warpbeam is also meant to contain them. Warpbeam is meant to back up your existing directory itself and restore it, from a single attribute to the whole directory. | Maturity 2 · usableCoverage 19 % |
| Data access governance | You see who can reach which data, and who owns it. | Maturity 0 · missingCoverage 0 % |
| Integration | ||
| Security events | Warpbeam collects security events; it is meant to analyse them with its own rules and answer them with defined playbooks. An existing analysis platform can be connected on top. | Maturity 2 · usableCoverage 14 % |
| IT service management | Requests, incidents and changes are meant to run in Warpbeam itself, with remote screen help started from the ticket. An existing ticketing system can be connected as well. | Maturity 1 · foundationCoverage 3 % |
| Secure service edge | Access to applications and to the internet is meant to run through our own gateways, in stages up to a filtering web gateway. | Maturity 1 · foundationCoverage 6 % |
| API | ||
| Identity API | One interface for all identity data and actions. | Maturity 2 · usableCoverage 16 % |
| Foundation | ||
| Relationships | Owners, managers, sponsors and the humans behind AI agents, kept in one place. | Maturity 1 · foundationCoverage 16 % |
| Orchestration | Workflows with approval and a four-eyes principle. The tools of IT operations are meant to run in Warpbeam itself as well: monitoring, software distribution and patching, device management, scripts on devices. | Maturity 2 · usableCoverage 9 % |
| Performance | Large environments are meant to stay fast, and Warpbeam is meant to measure this continuously in its own time series. | Maturity 1 · foundationCoverage 3 % |
| Resilience | Warpbeam keeps running when individual parts fail. It is meant to back up not only itself but also servers, virtual machines, files and cloud mailboxes, with tested restores. | Maturity 1 · foundationCoverage 9 % |
| Cross-cutting | ||
| AI control centre | The AI is meant to explain, recommend and act across six levels, under human control. The language model is meant to run inside Warpbeam itself. | Maturity 0 · missingnot measured, rated cautiously |
| Identity sovereignty | The goal is running without a third-party directory or sign-in service, with a guided exit. | Maturity 0 · missingnot measured, rated cautiously |
| Devices, mobile included | Devices are meant to become identities of their own, managed by Warpbeam itself, phones and tablets included. Existing device management can be connected on top. | Maturity 0 · missingnot measured, rated cautiously |
| Governance alignment | Your IT landscape is meant to be checked continuously against frameworks and your own policies, every finding sourced. | Maturity 0 · missingnot measured, rated cautiously |
| Compliance and evidence | Audit-ready evidence for common frameworks, with AI decisions marked as such. | Maturity 1 · foundationnot measured, rated cautiously |
Roadmap
The order, not the date.
We tell you what comes next and what comes after. We don't promise dates, only the order.
Today 98 of 2516 planned functions are built and 456 more partly – a coverage of 13 %.
-
Build the foundation
FirstBefore further capabilities are added, the foundation comes first, built in five waves, each closed by a check gate: the hardened Linux server in containers with roles you can switch on, secure connections to the agents, separated tenants, high availability and performance, the AI foundation, the identity API, metrics and evidence. We close open items in what exists first. The Linux server form is in place before the first delivery to customers; running Warpbeam as a service follows as a milestone of its own.
-
Machines, interfaces, first AI
NextMachines fetch their own secrets, APIs get a gateway of their own, AI agents become identities with runtime control. First AI functions: explaining findings, proposing actions, today's tasks, plus the emergency stop, rollback and a first learning mode.
-
Warpbeam as issuer
After thatWarpbeam signs users in to applications with its own sign-in service over open standards, with keys in a security module or the built-in key store. Plus web applications behind our own web proxy with a web application firewall, and access to applications without a VPN. No language model in the sign-in path. For identity sovereignty: the core of a directory of its own.
-
Governance at full breadth
After thatData access, review policies, ownership, segregation of duties, identity proofing. The AI recommends and explains; once it has passed learning mode, it may act on its own within limits. Widely used applications get connected. Sign-in to computers without a domain.
-
Operational maturity
OngoingThe remaining engines of our own: collecting and answering security events, the web gateway, the built-in AI runtime, server sessions with recording, and PDF reports. Plus events from the environment, IT service management, password self-service, our own certificate management with or without an existing Windows CA, device management with updates and software distribution, monitoring and backup, network access, compliance and data protection evidence, behaviour analytics, questions in plain language and a backup of your existing directory. And the migration tool, offered only as a service: moves between directories, mailboxes and file stores, including into a sovereign environment.
-
The whole fabric, sovereign
VisionAn AI control centre that also runs IT operations, as far as you allow. Operation entirely without a third-party directory. Devices, mobile included, as identities. Credentials from digital wallets as evidence during onboarding.