Sovereignty Starts with the login
Actually, the other day I just wanted to quickly access an app.
The login page opens.
Enter your email address.
A redirect to any identity provider.
Password.
MFA.
Something is spinning on the screen. Wait.
Then an error message that said something like: It’s not your fault, but it’s not entirely not your fault either.
So I went to get some coffee — an iced pour-over — because it was so hot.
Moments like these may seem insignificant. But they’re actually quite telling. After all, we only realize just how central digital identity has become when it doesn’t work properly. In the past, logging in was often just a minor technical feature. Today, almost everything depends on it: applications, portals, APIs, customer portals, partner accounts, and admin access. And your entire digital life on your phone.
Essentially, digital sovereignty begins right there. Not with a strategy paper, not with a policy speech, but with the question: Who actually controls access?
Who decides who is allowed to register?
Who decides which rights are granted?
Who can figure out what happened?
And who can operate the system, modify it, or switch to a different one if necessary?
I think it’s easy to underestimate this point. Because logging in has become such a routine part of life. It’s just there. Like salt in the kitchen. People rarely talk about it unless it’s missing or there’s too much of it.
It’s the same with identity management. When everything works, you hardly notice it. When it doesn’t work, everything suddenly comes to a standstill.
Keycloak is interesting to me in this context because it doesn’t try to hide these issues behind an obscure platform. And it doesn’t force a specific operating model on you (“only works in the cloud”), but instead offers many options and adapts to your needs. You can run Keycloak yourself, have it managed by a third party, customize it, extend it, and integrate it into various architectures.
That sounds less convenient than “just book and get started.” It probably is, too.
On the other hand, convenience isn’t always the same as control.
At some point, I realized that digital sovereignty rarely starts with grand concepts. Most of the time, it begins with very practical questions. For example, the question of whether you’re still in control of your own digital space when you log in.
This is likely to become even more relevant.
IAM Perspectives by Robert Bauer | intension
Robert Bauer is the Lead for Identity at intension and focuses on open-source IAM, Keycloak, and digital sovereignty in modern enterprise architectures.



