Digital identity is positioned as both a business enabler and a security control, becoming more critical as work becomes mobile and organizational boundaries overlap. Traditional onboarding is described as flawed because it relies on unvalidated directory records and treats directory enrollment as the start of trust, even though usernames and passwords are not meaningfully tied to real-world identity. As organizations increasingly rely on partners, suppliers, and contractors—often via federated arrangements—governance becomes difficult and visibility into “who has access to what” degrades, especially when partners further subcontract work. Manual onboarding between organizations (e.g., after mergers) is redundant, error-prone, and commonly devolves into assumed trust, while external service providers (e.g., physical security firms) can change staff rapidly without the customer having timely insight.
A core claim is that secure identity lifecycle management must begin with stronger onboarding: identity verification and identity data validation should establish a trusted user base. The text distinguishes validation (proving credentials/attributes exist, are current, and were issued by the right authority) from verification (linking those attributes to the correct individual). Because high-assurance KYC-style processes are costly for many non-regulated organizations, the proposed alternative is to leverage a network of verified identities—reusing assurance already established by national eID frameworks, financial institutions, certificate authorities, and related trust providers. The eIDAS levels of assurance (low, substantial, high) provide a standardized basis for determining whether an identity is sufficient for specific access requests and for enabling flexible MFA (smart cards, tokens, OTP/OTAC, mobile apps), SSO, and passwordless initiatives.
Liga’s GlobalID is presented as a platform that connects enterprise identity sources (HR systems, Active Directory, SAP) with authoritative validation methods (eID, passports, video identification) and authentication factors (CAs, tokens, apps), adding auditability, logging, and revocation to support governance and compliance.
See All Locations
See All Locations