Bootstrapping Identity Paper 07 of 07

Trust on first use, proof ever after

Many deployments begin without a single face image on file. This paper describes how biometric identity bootstraps from the trust an organization already holds, through one gated ceremony, and why the account that emerges is stronger than the one a password program ends with.

PDF, 7 pages Free, no card

The trust window is one ceremony wide, and it closes behind the first user.

Everything bootstraps on trust somewhere

SSH made the pattern explicit decades ago. The first connection to an unknown host presents a key, the user accepts it, and every later change is an alarm. The web runs quieter versions of the same move all day: an email verification link proves control of a mailbox for one moment, and an account is minted out of that moment.

So the useful comparison between systems is not whether they take the leap. Everybody takes it. It is what evidence gates the first use, and what the first use leaves behind. A password program answers badly on both counts, and nobody ever asks it the second question.

What the paper establishes

This is the deployment paper for organizations that hold no face images at all: no HR photo, no KYC file, nothing to mint from. Two doors lead into the same enrollment ceremony, and the paper spends its attention on the gates rather than on the ceremony behind them.

Then it does the part bootstrap designs usually skip. A first use is not only a risk to be survived. It also produces an account, and what that account can do afterward depends entirely on how it was made.

  • The two questions any trust-on-first-use design has to answer, and how a password bootstrap fails both
  • The provisioned-shell door and the self-signup door, and what anchors each one
  • How the email-domain allow-list is enforced so that probing it reveals nothing
  • The gating properties of the enrollment code itself, from storage to attempt caps to session uniqueness
  • A comparison of what three different bootstraps leave behind, and who can use the account afterward
  • The first-use hijack considered without flinching: what an attacker actually wins, and why it is worth so little

Who it is for

CIAM teams, B2B SaaS platforms, and any workforce deployment that cannot start from photos on file. Read it beside Biometrics on day one, which covers the path for organizations that can.

Be clear about what a trust window is. This design makes the window one ceremony wide and closes it behind the first user, but it does not remove the window, and the paper works through the first-use hijack instead of arguing it away.

Frequently asked questions

Do we need photos on file to deploy SenseCrypt?

No. A deployment with no face images is the normal case for customer identity and a common one for workforce identity. Users enroll through a SCIM-provisioned shell or through domain-gated self-signup, and the face token is minted on the user's own phone during the first ceremony.

Is self-signup an open door?

It is deliberately not a default. Each application must opt in, every signup lands in a designated group whose access is scoped in advance, and admissions can be restricted to approved email domains. The paper covers how that allow-list is enforced without leaking its own contents.

How long is it?

Seven pages, with two diagrams and a bootstrap comparison table.

Related reading

More in this series

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.