The door and the laptop are the same session.
When someone leaves, the badge stops working and the laptop locks, on site, in the same half-second. One Presence Session governs both planes, and one epoch ends them together.
Presence Sessions
When someone leaves, the badge stops working and the laptop locks, on site, in the same half-second. One Presence Session governs both planes, and one epoch ends them together.
Presence SessionsIncidents, catalog, service levels, the asset register, locations, requisitions, gate passes, and knowledge. Every one of them reading the identity graph the door already reads.
IT asset managementLogins, notes, and API keys held as ciphertext. The key comes from each member's own account password, so owning the workspace unwraps nothing at all.
VaultThe same binary either way. One database schema per workspace, your own domain on the front, and encryption key shares held by your custodians rather than by us.
Public sectorThe service desk and the asset register are here because the session authority has to know the custodian, the serial, and the approved exit. They are not the product. The Presence Session is.
Encrypted readers, camera frames on a three-second memory buffer, gait and face scored after the person is already through.
macOS EndpointSecurity and a Windows credential provider. Present, idle, locked, revoked.
Your directory stays authoritative. Cards are issued on your own equipment. Employment is attested without disclosing personal data.
Night shift can demand gait. Elevated threat can demand face. The compiler enforces the floor.
A durable log is the record. A retained site channel is the fan-out. Epochs only move forward.
Asset register, service desk, knowledge, and gate pass: the records the door already needed.
Asynchronous turnstiles release on the credential. Corroboration attaches to the session and can escalate the laptop, the next door, or the security team, rather than attempting a physically impossible retract.
Encrypted secure channel, local access list, epoch check. Under 80 ms. A legacy cleartext reader is a defect, not a fallback.
The credential named the person. Templates are compared only against that person's own enrollment, and the frames are dropped.
A tailgated entry marks the session. A presentation attack holds. A revocation ends the badge and the screen together.
A three-second buffer in memory. Keypoints live about 1.6 seconds. Plaintext templates are encrypted under a key sealed to the node's own hardware, then explicitly overwritten. The hosted service sees scores and metadata. It never sees a face.
European data protection law treats these templates as special-category data even when they only corroborate a claim. A policy carrying gait or face weight will not compile without a recorded lawful basis. Customer templates never train a shared model.
| Capability | Baselivery | Ticket-first suites |
|---|---|---|
| Badge and laptop as one session | One Presence Session, shared epochs | Separate access control, device management, and helpdesk |
| On-site revoke, both planes | p99 ≤ 500 ms | A ticket, then a wait for a human |
| Encrypted reader channel | Mandatory at every portal | Usually a third-party access control system |
| Edge biometrics without a cloud gallery | Site-local templates, gated on lawful basis | Vendor warehouse or nothing |
| CISO modality floor | Compiled policy, dual control to weaken | Firmware change or professional services |
| Employment attestation, no personal data | Signed attestation, no personal data | HR letter |
| Gate pass bound to the portal | Native, and readable by the policy engine | Email chain |
| ITSM / ITAM | Shipped, on the same identity graph | The whole product |
Lobbies stay fast. Secure areas interlock. Shared desks lock when the wrong person sits down.
Gait required on night shift. Contractors restricted at elevated threat. Approved exits at the dock.
Cash areas wait for corroboration. Two people required to weaken any control.
Residency, single-tenant deployment, local camera rules, and cryptographic erasure.
Why inert identity graphs are a security defect.
Demo, verification relying parties, disclosures.
We will walk you through a live portal, a compiled policy pack, and a revocation that closes the turnstile and locks the screen together. The asset register is already there when you need it.