Skip to content
warpbeam

Identity fabric

What is an identity fabric?

An identity fabric brings everything to do with identities and access together into one connected cloth. This page explains what the term means, how the reference architecture behind it is built, and how Warpbeam organises its capabilities along it.

StatusThis page explains a term and a model. It shows how the target state is organised, not how far it has got. How far each capability is, measured against the code, is on the roadmap.

The term

Many tools, one fabric.

In many organisations, managing identities is spread across many tools: one for accounts, one for sign-in, one for admin rights, one for reviews. Each has its own data and its own rules. Nobody has the full picture.

An identity fabric is a blueprint against this fragmentation. It describes which capabilities an organisation needs around identities and arranges them so that they work together: with shared data, shared rules and shared interfaces.

It covers every kind of identity. That means people, such as employees, contractors, partners and customers, and just as much devices, services and AI‑agents.

An identity fabric describes capabilities, not products. It says what is needed, such as strong sign-in or time-limited access, but not which tool provides it. That makes it a useful shared language: for planning, for looking at what you already have, and for deciding what comes next.

The picture behind the name Warpbeam fits: every identity is a warp thread, applications and access are the weft threads, and the cloth is the identity fabric. Warpbeam is the warp beam that holds every thread in one place. More on that in Why Warpbeam?

Ten kinds of identity

This is how the reference model distinguishes the identities an identity fabric is there for.

People

  • Employees
  • Contractors
  • Partners
  • Business customers
  • Consumers

Machines and services

  • Devices and the internet of things
  • Machines in operational technology
  • Service and functional accounts
  • Cloud services
  • AI‑agents and bots

Today Warpbeam manages people and service accounts. Machines and AI‑agents are meant to follow.

Reference architecture

Four A's and their layers.

A reference architecture makes the blueprint concrete. It breaks the identity fabric down into individual capabilities and sorts them into four areas, the four A's: administration, authentication, authorization and analytics. Around them sit layers for special tasks, for connecting other systems, for one shared interface and for the foundation.

On top of that come three points in time: beforehand, when accounts are created and access is granted; in the moment, when someone signs in and accesses something; afterwards, when things are reviewed, analysed and evidenced.

This is how Warpbeam maps the model: 29 capabilities, 24 of them from the model and 5 our own additions. Our own additions are marked. Capabilities carry the model's names where it has one.

The four A's

  • Administration

    Who belongs? Taking identities in, verifying and maintaining them, and bringing them into target systems.

    • Identity Repositories
    • Onboarding & Proofing
    • User Lifecycle Management
    • Identity Provisioning
    • Secrets Management
  • Authentication

    Is it really this person or this service? Sign-in and session.

    • Federation
    • Adaptive Authentication
    • Strong & Passwordless Authentication
    • Session Management
  • Authorization

    What may this identity do, right now? Roles, policies and time-limited access.

    • Static Authorization
    • Dynamic Authorization
    • Just-in-Time Access
    • Privilege Elevation
    • Web Access Management
  • Analytics and audit

    Is it still right? Reviewing access, spotting risks and anomalies.

    • Application Risk Management
    • Access Governance
    • Access Analytics
    • User Behaviour Analytics

Layers around the four A's

  • Extended

    Special tasks: protecting interfaces, detecting attacks on identities, governing access to data.

    • API Security
    • ITDR
    • Data Access Governance
  • Integration

    The link to security operations, IT service management and network access.

    • SIEM/SOAR
    • IT Service Management
    • Secure Service Edge
  • API

    One shared interface through which applications and partners use the identity services.

    • Identity API Layer own addition
  • Foundation

    What carries everything: relationships, orchestration, performance and resilience.

    • Identity Relationship Management own addition
    • Orchestration own addition
    • Performance own addition
    • Resilience own addition

Beyond the model

Warpbeam runs five topics across every area. The model does not list them as capabilities of their own. The roadmap shows them with their status, too.

AI control centre
The AI is meant to explain, recommend and act across six levels, under human control. The language model is meant to run inside Warpbeam itself.
Identity sovereignty
The goal is running without a third-party directory or sign-in service, with a guided exit.
Devices, mobile included
Devices are meant to become identities of their own, managed by Warpbeam itself, phones and tablets included. Existing device management can be connected on top.
Governance alignment
Your IT landscape is meant to be checked continuously against frameworks and your own policies, every finding sourced.
Compliance and evidence
Audit-ready evidence for common frameworks, with AI decisions marked as such.

Warpbeam

One model, one product.

The model itself is not a product but a blueprint. Each capability in it can come from a different tool.

Warpbeam goes one step further: every capability is meant to sit in one product, with one interface and one store of identities. Warpbeam is meant to deliver each one with an engine of its own. Existing systems can be connected, but they are not meant to be a prerequisite.

The structure also helps us stay honest. Every capability carries a maturity level from 0 to 4, measured against the code. How far each one is, is on the roadmap. How the parts work together and how Warpbeam is meant to run is shown on the architecture page.

Source

Where the model comes from.

Warpbeam organises its capabilities along the reference model “Identity Fabric & IAM Reference Architecture” by KuppingerCole. KuppingerCole is an analyst firm for identity and access management and publishes the model on its website.

Warpbeam is not a partner of KuppingerCole. KuppingerCole has not assessed, certified or recommended Warpbeam. The mapping to Warpbeam and our own additions are ours.

The reference model at KuppingerCole (external site)

KuppingerCole is a trademark of its owner. We use the name only to credit the source.