Identity fabric for every actor

One identity fabric.
Every access decision.

Model people, services, workloads and agents as principals. Resolve their relationships, assurance, provenance and risk into policy-ready context for authentication, tokens and authorization.

  • 01 Every actor is first class
  • 02 Context is versioned
  • 03 Access fails closed
Context resolved identity.heimdall.local ctxv:01892

Identity context

POLICY READY
RESOLVED PRINCIPAL12 ms
AGAgent principalexpense-assistant
Acting for
jane@northstar.io
Membership
Acme · active
Assurance
AAL2 · phishing resistant
Delegation
bounded · 42 min
Effective accessINTERSECTION
STANDARDS-ALIGNED FOUNDATION OAuth 2.1OpenID ConnectSAML 2.0SCIM 2.0WebAuthn
01 / IDENTITY FABRIC

Identity is more than
a user record.

Heimdall separates a principal from credentials, memberships, external accounts, directory sources, devices and security state. Each relationship keeps its own lifecycle, ownership and provenance.

PRINCIPALS HumanServiceWorkloadAgent
RELATIONSHIPS MembershipExternal identityDirectory sourceDevice & delegation
SIGNALS Typed attributesAuthentication assuranceSource & freshnessRisk & security state
IDENTITY CONTEXT RESOLVERBounded · versioned · policy ready Tokens · Authorization · Federation · Provisioning · Audit
ACTORS BEYOND PEOPLE

The common principal contract makes new identity types additive. Roadmap capabilities build on the same ownership, lifecycle and audit foundations instead of creating separate identity silos.

FOUNDATION

Service accounts

Named ownership, purpose, rotation and review for machine operations—distinct from the OAuth client requesting a token.

ROADMAP

Workload identities

Exchange trusted runtime assertions for short-lived, audience-bound credentials instead of distributing static keys.

ROADMAP

Agent identities

Give AI agents their own principal, runtime binding, tool policy, risk state and accountable owner.

ROADMAP

Delegation & devices

Keep actor and represented party separate, intersect authority, and carry time-bounded device trust into decisions.

02 / DECISION PATH

From identity evidence
to explainable access.

Runtime consumers receive a coherent identity view instead of rebuilding joins and provenance rules. Every stage stays bounded, auditable and explicit about the evidence it used.

IDENTITY CONTEXT

Resolve the actor and every relationship that matters.

Assemble organization membership, groups, attributes, assurance, device trust, delegation and security state into a bounded context with a version and expiry.

  • Requested attributes with provenance
  • Organization-scoped relationships
  • Stable reason codes and fail-closed outcomes
03 / CAPABILITIES

Seven pillars.
One coherent platform.

The capability catalogue groups Heimdall into seven market-facing pillars. Labels below distinguish shipped foundations from capability direction that advances through the product roadmap.

02
PROGRAMMABLE AUTHENTICATIONFOUNDATION

Compose the right journey

Versioned login flows bring hosted and headless experiences, MFA, passkeys, federation, recovery and risk-aware step-up into one runtime.

03
UNIVERSAL AUTHORIZATIONFOUNDATION

Decisions beyond roles

Compose RBAC, ABAC and ReBAC through one subject-action-resource-context model with reasons and obligations.

04
ADAPTIVE IDENTITY SECURITYADVANCING

Turn signals into response

Evaluate authentication, device, network and behavior signals. The roadmap extends risk decisions into continuous session response.

05
VERIFIED AUDIT LEDGERROADMAP

Evidence that can prove itself

Build from append-only audit events toward signed checkpoints, integrity proofs, immutable export and independent verification.

06
EXTENSIBLE IDENTITY RUNTIMEROADMAP

Extend within hard boundaries

Manifests, permissions and failure policies prepare authenticators, policies, connectors and flow nodes for isolated package execution.

07
DEPLOY ANYWHEREEXPANDING

Keep contracts consistent

Use the same APIs and configuration model across managed and customer-controlled environments as supported deployment profiles mature.

04 / ARCHITECTURE

One source of identity truth.
Two operating planes.

The control plane governs definitions, connections, lifecycle and publication. The data plane resolves, authenticates, authorizes and issues with bounded latency and explicit failure behavior.

  • 01
    Common principal contract

    Authorization, audit, ownership and token APIs refer to the same durable actor identity.

  • 02
    Bounded context resolution

    Consumers receive only authorized attributes, component versions and a clear validity window.

  • 03
    Isolation by construction

    Tenant context follows data through APIs, storage, cache, events and asynchronous work.

HEIMDALL / IDENTITY SYSTEM MAP BOUNDED
ENTRY SURFACES
Admin ConsoleHosted LoginManagement API
CONTROL PLANE
ConfigurePublishReview
DATA PLANE
ResolveDecideIssue
IDENTITY FABRIC & DOMAIN CORE
PrincipalRelationshipsAuthenticationFederationProvisioningAuthorizationRiskAudit
DATA & EVENTS
PostgreSQL + RLSRedisOutboxTelemetry
05 / DEPLOYMENT

Your identity plane.
Your operating boundary.

Heimdall keeps APIs, configuration and security semantics consistent while deployment profiles move from a shared application core toward stronger operational sovereignty.

MANAGED MODEL

Shared & dedicated SaaS

Operate identity without running the platform infrastructure, with isolation tiers designed around tenant boundaries and regional placement.

  • Consistent control and runtime APIs
  • Managed operations and upgrades
  • Isolation options by deployment profile
CUSTOMER CONTROLLED

Kubernetes & on-prem

Run supported profiles inside your network boundary with customer-held secrets, private connectivity and internal observability.

  • Separated runtime roles
  • Customer-controlled data systems
  • Provider adapters selected at deployment
PRODUCT DIRECTION

BYOC & air-gapped

Extend operational sovereignty into customer cloud accounts and, later, environments with no mandatory outbound dependency.

  • Preflight and upgrade orchestration
  • Offline diagnostics and support bundles
  • Consistent policy and extension contracts

Availability note. Deployment profiles, provider integrations and security certifications are release-specific. BYOC and air-gapped operation are roadmap capabilities, not current availability claims.

SECURITY BY CONSTRUCTION

Trust travels with the context.

Identity evidence stays scoped to the organization and consumer that requested it. Security-critical relationships fail closed, sensitive values stay out of events, and every decision can point to the context version it used.

DEFAULT DENYMissing context closes accessTENANT SCOPEDIsolation through every layerVERSIONEDEvidence, policy and lifecycle
IDENTITY WITHOUT SILOS

Give every actor
a clear identity.

Build authentication, authorization and lifecycle on one model for people, machines and the agents that act between them.