How do IAM models differ from the user's point of view, and what are examples of each class?
Externally determined identities are issued and controlled by an identity service; user-centric identities are controlled by the subject, either partially (issued by a service, held by the subject, as in PKI certificates or the Swiss E-ID) or fully (issued and controlled by the subject, the SSI vision).
* From externally determined to fully self-sovereign: control over the identity moves step by step to the subject. *
| Externally determined | User-centric, partially controlled | User-centric, fully controlled | |
|---|---|---|---|
| Issuer of the identity | Identity service | Identity service | Subject |
| Control over the identity | Identity service | Subject | Subject |
| Examples | Classical identities (federation, provisioning) | PKI: X.509 certificates, the German nPA, the Swiss E-ID | Self-sovereign identity (vision) |
The dividing line is control: who holds the identity data and decides when it is used. With a classical account, the service holds everything and is part of every login. With a certificate or an E-ID credential, the service issues it once, but the subject keeps it and presents it without the issuer being involved. The fully self-sovereign case, where even the issuing is in the subject's hands, is still a vision rather than everyday practice.
Go deeper:
X.509 (Wikipedia) — the certificate standard behind the partially user-controlled class: issued by a CA, held and used by the subject.