Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders Heather Flanagan, Spherical Cow Consulting, Beyond Borders But that's a policy decision, that's fine, it's not a failure.
But if the system can't see that distinction, explain it or route around it, then the difference turns into you've just damaged something, you've broken it, you've fragmented how all of this is supposed to work. So perhaps a better design target is not this is going to work everywhere. Maybe it's this works predictably within defined trust boundaries and fails cleanly when outside them. It's a less glamorous than universal interoperability, but it also survives contact with reality a little bit better.
So I'm not sure that sounded like, okay, yes, that's awesome, that's great, but what am I supposed to do with this other than be intellectually stimulated? Which I hope you are, let's be clear. I tried to say, well, what are things that you would need to think about when you go home? What are like the five questions that you would wanna be asking yourself? And if you think that the first question is, well, okay, but which wallet then should I support or which vendor should I buy a product from?
No, bad, go back, don't do that. That's not the point at all. What you need to do is actually start hunting down where your assumptions are hiding, because that's where you're gonna need to build in some of those resilience patterns that you might not already have. For example, where are your quiet dependencies? Are you depending on a browser API? Are you depending on a particular mobile platform, a cloud provider, a trust registry, a particular data source?
I mean, many identity systems look like they are distributed across these things, except if you suddenly take something out and the whole system fails, that's not actually a functional distribution. Next thing you wanna ask, okay, there's cross-border assumptions. What have you actually tested? Do the assurance levels mean the same thing from one region to the next, to the next across the markets that you're working in? Are your issuers trusted, right? Can the same data be used for the same purpose? Sometimes yes, sometimes no.
Does the same consent flow actually work or do you have to make sure that that's modular and you can put something in and pull something out depending on the situation you're working in? I mean, there's more to it than that. And you can always go check the slides and the speaking notes if you want more gory details.
I mean, the processes you have in an enterprise tend to look really responsible, right? When you actually make the system harder to use, because then you're like, look, I am going to push the hard questions and I'm gonna force everything to go to the user and say, are you okay with this? What about now? What about now? What about now? Is now okay?
You know, that's a trap. I want to avoid friction where I can. I want to have things be modular so that you can swap in and out as you need to and have it be a more cleaner environment. If you've fallen into the trap of mistaking procedural weight for actual trust, you're gonna have a problem. If the extra steps that you've got in there does not clarify who's trusted, for what purpose and under what conditions, then actually all you're doing is adding friction and it's not helping the world. So here we are, right?
The global internet, always partially aspirational as much as some organizations have that as their whole call sign. We are aiming for a global internet.
Okay, it's a good goal, but you're not going to get there. That aspiration is always dependent on the hope that shared protocols and open standards would just carry us across all the political divides and legal concerns and economic challenges that are out there. I appreciate the hope. It actually did get us very far if you think about it. But what the identity space shows us is where the limits of that hope end up, right? Identity systems do not only run on technical interoperability. They run on a human trust, recognition, liability, governments, platform behavior and policy.
And those do not automatically align because the technology works. So we're now entering a more negotiated era. Doesn't mean failure. I'm not going to tell anyone who's ever talked to a diplomat that negotiation means failure, no. But it does mean that our work as identity professionals has possibly changed. The challenge isn't that you need to make the system connect. It's that you need to make them work predictably across disagreement. And that makes knowing that you need to know your trust boundaries. You need to make policy decisions visible. You need to design your fallback paths.
You need to be honest about the technical maturity that is not yet up to political ambition. So goal here, we're not aiming for perfect harmonization. You're not going to get that. The goal is resilience, keeping the ordinary divergence that you've got from becoming operational fragmentation and keeping that fragmentation from causing user harm. Congratulations, you have graduated from being an identity professional to being a identity diplomat. The end. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you.
Thank you, Heather, for finishing well on time. Time for a question. We do have a questions coming from the audience. From your perspective in standards and interoperability, what's the one thing you would change? That's a pretty tough question, I have to admit. So if I was queen of the universe, which I'm not, but if I was, one, I would have an awesome tiara.
And two, the biggest difficulty I tend to see in the standards process overall is that conflict between you've got policy people coming in saying, we are setting the laws to do this, the technology people saying, we don't even actually know how to technically do that in a way that complies with everything else. And that makes it a really complicated problem. I'm not morally opposed to complicated problems, but if you have a complicated problem, you need people, places, and things that have enough resources to throw at it to try and answer the problem. Who's that?
It's not a small business for the most part. That's where you get your tech heavy engagement because problems of this level of complexity aren't something generally, you're either gonna get a government involved or you're gonna get a big tech company involved because anyone smaller than that for the most part can't engage to the level that's necessary to solve the super complicated things. And everybody hates big tech. And if you don't hate big tech, you hate government. So it's like, so if I could solve that tension, I would earn that tiara.
Yes, yes. Thank you, Heather. Thank you.