Service accounts
Named ownership, purpose, rotation and review for machine operations—distinct from the OAuth client requesting a token.
Model people, services, workloads and agents as principals. Resolve their relationships, assurance, provenance and risk into policy-ready context for authentication, tokens and authorization.
Identity context
POLICY READYHeimdall separates a principal from credentials, memberships, external accounts, directory sources, devices and security state. Each relationship keeps its own lifecycle, ownership and provenance.
The common principal contract makes new identity types additive. Roadmap capabilities build on the same ownership, lifecycle and audit foundations instead of creating separate identity silos.
Named ownership, purpose, rotation and review for machine operations—distinct from the OAuth client requesting a token.
Exchange trusted runtime assertions for short-lived, audience-bound credentials instead of distributing static keys.
Give AI agents their own principal, runtime binding, tool policy, risk state and accountable owner.
Keep actor and represented party separate, intersect authority, and carry time-bounded device trust into decisions.
Runtime consumers receive a coherent identity view instead of rebuilding joins and provenance rules. Every stage stays bounded, auditable and explicit about the evidence it used.
Assemble organization membership, groups, attributes, assurance, device trust, delegation and security state into a bounded context with a version and expiry.
The capability catalogue groups Heimdall into seven market-facing pillars. Labels below distinguish shipped foundations from capability direction that advances through the product roadmap.
Unify users, organizations, groups, service accounts, external identities, lifecycle and SCIM around durable principals and first-class relationships.
Versioned login flows bring hosted and headless experiences, MFA, passkeys, federation, recovery and risk-aware step-up into one runtime.
Compose RBAC, ABAC and ReBAC through one subject-action-resource-context model with reasons and obligations.
Evaluate authentication, device, network and behavior signals. The roadmap extends risk decisions into continuous session response.
Build from append-only audit events toward signed checkpoints, integrity proofs, immutable export and independent verification.
Manifests, permissions and failure policies prepare authenticators, policies, connectors and flow nodes for isolated package execution.
Use the same APIs and configuration model across managed and customer-controlled environments as supported deployment profiles mature.
The control plane governs definitions, connections, lifecycle and publication. The data plane resolves, authenticates, authorizes and issues with bounded latency and explicit failure behavior.
Authorization, audit, ownership and token APIs refer to the same durable actor identity.
Consumers receive only authorized attributes, component versions and a clear validity window.
Tenant context follows data through APIs, storage, cache, events and asynchronous work.
Heimdall keeps APIs, configuration and security semantics consistent while deployment profiles move from a shared application core toward stronger operational sovereignty.
Operate identity without running the platform infrastructure, with isolation tiers designed around tenant boundaries and regional placement.
Run supported profiles inside your network boundary with customer-held secrets, private connectivity and internal observability.
Extend operational sovereignty into customer cloud accounts and, later, environments with no mandatory outbound dependency.
Availability note. Deployment profiles, provider integrations and security certifications are release-specific. BYOC and air-gapped operation are roadmap capabilities, not current availability claims.
Identity evidence stays scoped to the organization and consumer that requested it. Security-critical relationships fail closed, sensitive values stay out of events, and every decision can point to the context version it used.
Build authentication, authorization and lifecycle on one model for people, machines and the agents that act between them.