Digital Identity.
The set of attributes, credentials, and relationships that represent a person, organization, or service in a digital system, the thing CIAM platforms exist to manage.
The four forms of digital identity
The four forms of digital identity describe who issues an identity and who controls it. Christopher Allen's essay The Path to Self-Sovereign Identity set out this progression, and it is still the clearest way to compare identity models.
- Centralized identity. One organisation issues and holds the identity, such as a username and password on a single website. The organisation can revoke it at any time, and it does not travel.
- Federated identity. An identity provider issues the identity and other services trust it, through protocols such as SAML and OpenID Connect. "Sign in with Google" and enterprise single sign-on are federated identity.
- User-centric identity. The person chooses which identifier to use and carries it between services, as early OpenID and today's social login attempt. Control is shared between the person and the provider.
- Self-sovereign identity. The person holds verifiable credentials in their own wallet and shares only what a service needs. Early blockchain-based products in this space included Evernym, acquired by Avast in 2021, and ShoCard, acquired by Ping Identity in 2020. The EU Digital Identity Wallet and mobile driving licences are the mainstream form in 2026.
A second, equally common reading groups digital identities by the kind of entity they represent: people (customers and employees), organisations, devices, and software (workloads, APIs, and AI agents). CIAM manages the first; workforce IAM, device management, and non-human identity tools manage the others.
Digital identity examples
- An online banking or shopping account with a password or passkey
- A Sign in with Google or Sign in with Apple account used across many apps
- A government digital ID, such as a mobile driving licence or national eID
- An employee single sign-on account in a workforce identity provider
- A device certificate that proves a laptop is company-managed
- The OAuth client credentials an AI agent uses to call an API
Digital identity and CIAM
Digital identity is the noun; CIAM, workforce IAM, and NHI are the systems that manage instances of it. Conflating the concept with the system is a common cause of stuck conversations. A buyer asking "do you do digital identity?" usually means something specific (consumer login, employee SSO, agent auth) that maps to a specific tool class.
The 2026 frontier is non-human digital identity. AI agents, MCP servers, autonomous workflows, and service accounts all need first-class digital identities with their own attributes, credentials, and audit trails, distinct from the human users they may act on behalf of. Treating an agent as a special-case user is the architectural shortcut that produces the worst agentic-AI security incidents.
Go deeper: A comprehensive guide to MCP explains how AI agents and MCP servers extend their capabilities, and why each needs an identity of its own.
Common questions
What is digital identity?
A digital identity is the set of attributes, credentials, and relationships a system uses to recognise a person, organisation, device, or software agent and decide what it may do. It includes identifiers such as an email address, credentials such as a password or passkey, and records such as login history and granted permissions.
What are the four forms of digital identity?
The four forms usually describe who controls the identity. Centralized identity is issued and held by one provider, such as a website account. Federated identity is issued by one provider and trusted by others, such as signing in with Google. User-centric identity lets the person choose and carry identifiers across services. Self-sovereign identity puts the person in control of verifiable credentials held in their own wallet.
What are examples of digital identity?
Common examples are an online banking login, a social media profile, and a Sign in with Google or Apple account. Others include a government digital ID or mobile driving licence, an employee SSO account, a device certificate on a laptop, and the credentials an AI agent uses to call an API.
What is the difference between digital identity and CIAM?
Digital identity is the thing being managed: the attributes and credentials that represent someone. Customer identity and access management (CIAM) is the system that manages customer digital identities at scale, handling registration, login, profile data, consent, and security for customer-facing applications.
What are the NIST SP 800-63 digital identity guidelines?
NIST Special Publication 800-63 is the US government's digital identity guideline. Revision 4 splits the lifecycle into identity proofing and enrollment (800-63A), authentication and authenticator management (800-63B), and federation and assertions (800-63C), each with assurance levels that set how strong each step must be.
Related terms
In the guides
B2B SaaS Identity: Organizations, SSO, SCIM, and the Enterprise Sales Checklist
How to design B2B SaaS identity: Organizations, Enterprise SSO with SAML and OIDC, SCIM provisioning, audit logs, and the IT-admin features that close enterprise deals.
Decentralized Identity and Verifiable Credentials: What CIAM Teams Should Know
EUDI Wallet rolls out in 2026. US mDL adoption is uneven but real. DID and VC are no longer research projects. The CIAM-side impact, and when to start integrating.
SSO vs Federation: One Login Across Apps, or One Identity Across Domains
SSO is a user experience: one login unlocks many apps. Federation is the protocol mechanism that trusts another organization's identity assertions. SSO uses federation; they aren't the same.