Skip to content
warpbeam

Roadmap

What runs. What's next.

The identity fabric is the cloth. Here you see how densely it is woven today: every capability, structured along a widely used reference model, each with a measured status. Plus the order in which we build, without promising dates.

Status23 September 2026, measured against the code. Maturity 0 missing, 1 foundation, 2 usable (the core flow runs in our test environment), 3 extensive, 4 complete. Coverage: share of planned functions that is built; partly built counts half. Today no capability is extensive or complete. Warpbeam is not yet for sale; this site provides information about the software.

Weave

How densely the fabric is woven today.

Every vertical line stands for a capability: the thicker, the further along it is today. Every phase is a row across; a knot shows which capabilities it moves forward. Pick a phase or a capability.

The assignment comes from our target picture; 2 capabilities are not assigned to a phase yet and show as “not scheduled yet”.

  • Maturity 0 · missing dashed
  • Maturity 1 · foundation thin
  • Maturity 2 · usable medium
  • Maturity 3 · extensive thick
  • Maturity 4 · complete thickest
  • Knot This phase moves the capability forward.

The graphic scrolls sideways. Everything is also listed below.

On narrow screens, only the phases are listed here. The table below shows every capability with its status.

Phases

  1. Phase F: Build the foundation

    Before further capabilities are added, the foundation comes first, built in five waves, each closed by a check gate: the hardened Linux server in containers with roles you can switch on, secure connections to the agents, separated tenants, high availability and performance, the AI foundation, the identity API, metrics and evidence. We close open items in what exists first. The Linux server form is in place before the first delivery to customers; running Warpbeam as a service follows as a milestone of its own.

    Moves forward in the target picture: Secrets, Adaptive authentication, Dynamic authorization, Privilege elevation, Access governance, Access analytics, API security, Security events, Identity API, Orchestration, Performance, Resilience.

  2. Phase A: Machines, interfaces, first AI

    Machines fetch their own secrets, APIs get a gateway of their own, AI agents become identities with runtime control. First AI functions: explaining findings, proposing actions, today's tasks, plus the emergency stop, rollback and a first learning mode.

    Moves forward in the target picture: Identity repository, Secrets, Dynamic authorization, Just-in-time access, API security, Relationships.

  3. Phase B: Warpbeam as issuer

    Warpbeam signs users in to applications with its own sign-in service over open standards, with keys in a security module or the built-in key store. Plus web applications behind our own web proxy with a web application firewall, and access to applications without a VPN. No language model in the sign-in path. For identity sovereignty: the core of a directory of its own.

    Moves forward in the target picture: Federation, Web access management, Secure service edge.

  4. Phase C: Governance at full breadth

    Data access, review policies, ownership, segregation of duties, identity proofing. The AI recommends and explains; once it has passed learning mode, it may act on its own within limits. Widely used applications get connected. Sign-in to computers without a domain.

    Moves forward in the target picture: Identity repository, Onboarding and proofing, Lifecycle, Provisioning, Roles and policies, Application risk, Access governance, Data access governance, IT service management, Relationships.

  5. Phase D: Operational maturity

    The remaining engines of our own: collecting and answering security events, the web gateway, the built-in AI runtime, server sessions with recording, and PDF reports. Plus events from the environment, IT service management, password self-service, our own certificate management with or without an existing Windows CA, device management with updates and software distribution, monitoring and backup, network access, compliance and data protection evidence, behaviour analytics, questions in plain language and a backup of your existing directory. And the migration tool, offered only as a service: moves between directories, mailboxes and file stores, including into a sovereign environment.

    Moves forward in the target picture: Sessions, Access analytics, Behaviour analytics, Security events.

Capabilities

  1. Identity repository

    Maturity 2 · usable

    Coverage 17 %: 8 of 142 planned functions built, 33 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase A, Phase C.

  2. Onboarding and proofing

    Maturity 1 · foundation

    Coverage 3 %: 0 of 70 planned functions built, 4 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase C.

  3. Lifecycle

    Maturity 1 · foundation

    Coverage 15 %: 2 of 102 planned functions built, 26 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase C.

  4. Provisioning

    Maturity 2 · usable

    Coverage 17 %: 4 of 157 planned functions built, 44 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase C.

  5. Secrets

    Maturity 2 · usable

    Coverage 14 %: 14 of 252 planned functions built, 41 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase A.

  6. Federation

    Maturity 1 · foundation

    Coverage 5 %: 1 of 86 planned functions built, 6 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase B.

  7. Adaptive authentication

    Maturity 2 · usable

    Coverage 29 %: 14 of 83 planned functions built, 20 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase F.

  8. Strong and passwordless sign-in

    Maturity 2 · usable

    Coverage 13 %: 3 of 71 planned functions built, 13 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: not scheduled yet.

  9. Sessions

    Maturity 1 · foundation

    Coverage 13 %: 3 of 63 planned functions built, 10 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase D.

  10. Roles and policies

    Maturity 2 · usable

    Coverage 15 %: 4 of 110 planned functions built, 24 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase C.

  11. Dynamic authorization

    Maturity 2 · usable

    Coverage 19 %: 2 of 43 planned functions built, 12 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase A.

  12. Just-in-time access

    Maturity 2 · usable

    Coverage 18 %: 2 of 46 planned functions built, 13 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase A.

  13. Privilege elevation

    Maturity 1 · foundation

    Coverage 25 %: 6 of 42 planned functions built, 9 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase F.

  14. Web access management

    Maturity 1 · foundation

    Coverage 1 %: 0 of 35 planned functions built, 1 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase B.

  15. Application risk

    Maturity 1 · foundation

    Coverage 9 %: 0 of 74 planned functions built, 14 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase C.

  16. Access governance

    Maturity 2 · usable

    Coverage 12 %: 2 of 119 planned functions built, 24 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase C.

  17. Access analytics

    Maturity 2 · usable

    Coverage 30 %: 4 of 46 planned functions built, 20 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase D.

  18. Behaviour analytics

    Maturity 2 · usable

    Coverage 21 %: 2 of 53 planned functions built, 18 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase D.

  19. API security

    Maturity 2 · usable

    Coverage 7 %: 2 of 106 planned functions built, 11 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase A.

  20. Identity threat detection and response

    Maturity 2 · usable

    Coverage 19 %: 8 of 127 planned functions built, 31 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: not scheduled yet.

  21. Data access governance

    Maturity 0 · missing

    Coverage 0 %: 0 of 62 planned functions built, 0 partly.

    Next step: build first functions so the foundation stands. Phase: Phase C.

  22. Security events

    Maturity 2 · usable

    Coverage 14 %: 3 of 64 planned functions built, 12 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase F, Phase D.

  23. IT service management

    Maturity 1 · foundation

    Coverage 3 %: 0 of 77 planned functions built, 5 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase C.

  24. Secure service edge

    Maturity 1 · foundation

    Coverage 6 %: 0 of 71 planned functions built, 8 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase B.

  25. Identity API

    Maturity 2 · usable

    Coverage 16 %: 5 of 58 planned functions built, 8 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase F.

  26. Relationships

    Maturity 1 · foundation

    Coverage 16 %: 1 of 32 planned functions built, 8 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase A, Phase C.

  27. Orchestration

    Maturity 2 · usable

    Coverage 9 %: 7 of 195 planned functions built, 23 partly.

    Next step: raise coverage to at least three quarters (extensive). Phase: Phase F.

  28. Performance

    Maturity 1 · foundation

    Coverage 3 %: 0 of 29 planned functions built, 2 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase F.

  29. Resilience

    Maturity 1 · foundation

    Coverage 9 %: 1 of 101 planned functions built, 16 partly.

    Next step: get the core flow running end to end (usable). Phase: Phase F.

Capabilities

Every capability at a glance.

Maturity 0 · missing 1 Maturity 1 · foundation 12 Maturity 2 · usable 16 Maturity 3 · extensive 0 Maturity 4 · complete 0 (29 measured capabilities; plus 5 cross-cutting items, not measured)

Filter by status
Warpbeam capabilities with their status, as of 23 September 2026
CapabilityTarget: what it is meant to do for youStatus
Administration
Identity repositoryEvery identity in one place, with its origin and history.Maturity 2 · usableCoverage 17 %
Onboarding and proofingNew identities are verified before they get any access.Maturity 1 · foundationCoverage 3 %
LifecycleJoiners, movers and leavers take effect everywhere, driven from HR.Maturity 1 · foundationCoverage 15 %
ProvisioningAccounts and access appear in target systems on their own, and disappear again.Maturity 2 · usableCoverage 17 %
SecretsPasswords and keys for people and machines live in a vault, not in scripts. Certificates are found, issued, deployed and renewed – with an own certificate authority, even without any directory service.Maturity 2 · usableCoverage 14 %
Authentication
FederationApplications are meant to sign users in over OIDC, OAuth and SAML, with Warpbeam's own sign-in service as the issuer.Maturity 1 · foundationCoverage 5 %
Adaptive authenticationRisky sign-ins are spotted and held.Maturity 2 · usableCoverage 29 %
Strong and passwordless sign-inMultiple factors and passkeys instead of a password alone.Maturity 2 · usableCoverage 13 %
SessionsActive sessions can be seen and ended. Sessions on servers (RDP, SSH) are meant to run through an engine of our own, with recording.Maturity 1 · foundationCoverage 13 %
Authorization
Roles and policiesWho may do what follows from roles and rules, not one-off exceptions.Maturity 2 · usableCoverage 15 %
Dynamic authorizationAccess takes the situation into account: device, location, risk.Maturity 2 · usableCoverage 19 %
Just-in-time accessAdmin rights exist only for as long as they are needed.Maturity 2 · usableCoverage 18 %
Privilege elevationAdmins work with normal accounts and elevate only when needed.Maturity 1 · foundationCoverage 25 %
Web access managementWeb applications are meant to be protected by our own web proxy with its own web application firewall, even without a sign-in of their own.Maturity 1 · foundationCoverage 1 %
Analytics and audit
Application riskRisky combinations of rights inside applications are detected, for example segregation of duties.Maturity 1 · foundationCoverage 9 %
Access governanceOwners confirm access regularly, with evidence. Risks, suppliers and your own controls are meant to live in one register, with evidence for auditors.Maturity 2 · usableCoverage 12 %
Access analyticsSurplus and unusual access becomes visible.Maturity 2 · usableCoverage 30 %
Behaviour analyticsUnusual account behaviour stands out.Maturity 2 · usableCoverage 21 %
Extended
API securityMachines and tools get in only with their own, limited identity.Maturity 2 · usableCoverage 7 %
Identity threat detection and responseAttacks on identities are detected; Warpbeam is also meant to contain them. Warpbeam is meant to back up your existing directory itself and restore it, from a single attribute to the whole directory.Maturity 2 · usableCoverage 19 %
Data access governanceYou see who can reach which data, and who owns it.Maturity 0 · missingCoverage 0 %
Integration
Security eventsWarpbeam collects security events; it is meant to analyse them with its own rules and answer them with defined playbooks. An existing analysis platform can be connected on top.Maturity 2 · usableCoverage 14 %
IT service managementRequests, incidents and changes are meant to run in Warpbeam itself, with remote screen help started from the ticket. An existing ticketing system can be connected as well.Maturity 1 · foundationCoverage 3 %
Secure service edgeAccess to applications and to the internet is meant to run through our own gateways, in stages up to a filtering web gateway.Maturity 1 · foundationCoverage 6 %
API
Identity APIOne interface for all identity data and actions.Maturity 2 · usableCoverage 16 %
Foundation
RelationshipsOwners, managers, sponsors and the humans behind AI agents, kept in one place.Maturity 1 · foundationCoverage 16 %
OrchestrationWorkflows with approval and a four-eyes principle. The tools of IT operations are meant to run in Warpbeam itself as well: monitoring, software distribution and patching, device management, scripts on devices.Maturity 2 · usableCoverage 9 %
PerformanceLarge environments are meant to stay fast, and Warpbeam is meant to measure this continuously in its own time series.Maturity 1 · foundationCoverage 3 %
ResilienceWarpbeam keeps running when individual parts fail. It is meant to back up not only itself but also servers, virtual machines, files and cloud mailboxes, with tested restores.Maturity 1 · foundationCoverage 9 %
Cross-cutting
AI control centreThe AI is meant to explain, recommend and act across six levels, under human control. The language model is meant to run inside Warpbeam itself.Maturity 0 · missingnot measured, rated cautiously
Identity sovereigntyThe goal is running without a third-party directory or sign-in service, with a guided exit.Maturity 0 · missingnot measured, rated cautiously
Devices, mobile includedDevices are meant to become identities of their own, managed by Warpbeam itself, phones and tablets included. Existing device management can be connected on top.Maturity 0 · missingnot measured, rated cautiously
Governance alignmentYour IT landscape is meant to be checked continuously against frameworks and your own policies, every finding sourced.Maturity 0 · missingnot measured, rated cautiously
Compliance and evidenceAudit-ready evidence for common frameworks, with AI decisions marked as such.Maturity 1 · foundationnot measured, rated cautiously

Roadmap

The order, not the date.

We tell you what comes next and what comes after. We don't promise dates, only the order.

Today 98 of 2516 planned functions are built and 456 more partly – a coverage of 13 %.

  1. Build the foundation

    First

    Before further capabilities are added, the foundation comes first, built in five waves, each closed by a check gate: the hardened Linux server in containers with roles you can switch on, secure connections to the agents, separated tenants, high availability and performance, the AI foundation, the identity API, metrics and evidence. We close open items in what exists first. The Linux server form is in place before the first delivery to customers; running Warpbeam as a service follows as a milestone of its own.

  2. Machines, interfaces, first AI

    Next

    Machines fetch their own secrets, APIs get a gateway of their own, AI agents become identities with runtime control. First AI functions: explaining findings, proposing actions, today's tasks, plus the emergency stop, rollback and a first learning mode.

  3. Warpbeam as issuer

    After that

    Warpbeam signs users in to applications with its own sign-in service over open standards, with keys in a security module or the built-in key store. Plus web applications behind our own web proxy with a web application firewall, and access to applications without a VPN. No language model in the sign-in path. For identity sovereignty: the core of a directory of its own.

  4. Governance at full breadth

    After that

    Data access, review policies, ownership, segregation of duties, identity proofing. The AI recommends and explains; once it has passed learning mode, it may act on its own within limits. Widely used applications get connected. Sign-in to computers without a domain.

  5. Operational maturity

    Ongoing

    The remaining engines of our own: collecting and answering security events, the web gateway, the built-in AI runtime, server sessions with recording, and PDF reports. Plus events from the environment, IT service management, password self-service, our own certificate management with or without an existing Windows CA, device management with updates and software distribution, monitoring and backup, network access, compliance and data protection evidence, behaviour analytics, questions in plain language and a backup of your existing directory. And the migration tool, offered only as a service: moves between directories, mailboxes and file stores, including into a sovereign environment.

  6. The whole fabric, sovereign

    Vision

    An AI control centre that also runs IT operations, as far as you allow. Operation entirely without a third-party directory. Devices, mobile included, as identities. Credentials from digital wallets as evidence during onboarding.