LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

How do IAM models differ from the user's point of view, and what are examples of each class?

Externally determined identities are issued and controlled by an identity service; user-centric identities are controlled by the subject, either partially (issued by a service, held by the subject, as in PKI certificates or the Swiss E-ID) or fully (issued and controlled by the subject, the SSI vision).

Three classes stacked: externally determined, user-centric partially controlled, user-centric fully controlled, with control moving to the subject

* From externally determined to fully self-sovereign: control over the identity moves step by step to the subject. *

Externally determined User-centric, partially controlled User-centric, fully controlled
Issuer of the identity Identity service Identity service Subject
Control over the identity Identity service Subject Subject
Examples Classical identities (federation, provisioning) PKI: X.509 certificates, the German nPA, the Swiss E-ID Self-sovereign identity (vision)

The dividing line is control: who holds the identity data and decides when it is used. With a classical account, the service holds everything and is part of every login. With a certificate or an E-ID credential, the service issues it once, but the subject keeps it and presents it without the issuer being involved. The fully self-sovereign case, where even the issuing is in the subject's hands, is still a vision rather than everyday practice.

Go deeper:

  • doc X.509 (Wikipedia) — the certificate standard behind the partially user-controlled class: issued by a CA, held and used by the subject.

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026