Deployment Paper 05 of 07

Biometrics on day one

Strong authentication programs rarely fail on cryptography; they fail on enrollment. This paper describes an identity platform whose coverage begins with photos the organization already holds, not with a ceremony every user must complete.

PDF, 6 pages Free, no card

Coverage exists before the first user acts.

Programs fail on logistics, not mathematics

Any credential that needs a per-user enrollment ceremony produces the same deployment shape, whatever the credential is. Engaged users enroll in the first weeks. Then the curve flattens into a long tail: staff on leave, contractors, frontline workers with no corporate mailbox, executives whose calendars absorb every reminder campaign.

That tail is not cosmetic. While it stays open, the password or one-time-code fallback stays enabled for anyone who asks, and attackers pick the fallback rather than confront the new factor. The exposure the program was funded to close outlives the program.

What the paper establishes

The paper inverts the dependency. Instead of coverage waiting on each user to act, each user arrives to find coverage already waiting for them. That inversion is the short part of the paper, because it is the easy part.

Most of the length goes to the part that decides whether the deployment still holds in year two, which is not the mint at all. It is everything that happens to an account after it.

  • The three compounding costs of a ceremony-first rollout, including the one that never ends
  • How enrollment becomes a batch operation, and what happens to each photo along the way
  • The two paths for populations that arrive with no images at all
  • Joiners, movers, and leavers: how each transition stays anchored to the directory rather than drifting
  • How appearance change is absorbed without silent template adaptation
  • Three capabilities deliberately not built, and why each absence is a security property

Who it is for

Programme owners and IAM architects sizing a rollout, and anyone who has watched an enrollment curve flatten before the legacy path could be retired. Bring the lifecycle section to an operations review, not to a security review.

It assumes you have images to start from. If your directory holds no photos at all, which is the normal case for customer identity, this is the wrong paper: read Trust on first use, proof ever after instead.

Frequently asked questions

What if we hold no photos at all?

That is the normal case for customer identity and a common one for workforce identity, and it has its own paper in this series: Trust on first use, proof ever after. This paper covers the two no-photo paths briefly and points there for the detail.

What happens to the photos used for the batch mint?

Each image is forwarded in memory to a firewalled minting service and dropped once the token exists. It never touches disk, a database, or a log line. The paper covers the two alternative paths where no image is involved at any point.

How long is it?

Six pages, with a rollout-curve comparison and an account lifecycle diagram.

Related reading

More in this series

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.