The word in the golem’s head

Before the move, the thing that let everyone in was already Golem Trust’s own, and that was the good news. Keycloak, self-hosted, was the keeper of keys, the word written in the golem’s head, an identity provider Golem Trust ran rather than rented. The catch was not the keeper. It was the doors the keeper had agreed to trust: the Royal Bank federates in through Microsoft, and its own deception layer scatters bait across a Microsoft product. The scraps for this layer say: an identity a firm runs itself can still open, at its edge, onto a company it does not.

The keeper

Keycloak stays. It is an incubation project of the Cloud Native Computing Foundation, the code is open and runs anywhere, and Golem Trust runs it on its own machines, so the identity that lets staff and services reach everything is not a tenant of any outside company. The root of it is not even a password: the account of last resort is Mr Pump’s own chem, the words in a golem’s head, which has the rare merit that it cannot be phished, forwarded or federated, there being only the one of him and no record of him ever handing it over. This is the layer most providers get wrong and Golem Trust got right early, and the move does not touch it beyond writing down why it is sound.

The customer’s edge

The Royal Bank signs in through its own Microsoft, federated to Keycloak over SAML, so the bank’s people arrive already vouched for by Active Directory Federation Services. That is a Microsoft dependency, and it is the customer’s, not Golem Trust’s: it did not put Microsoft under its own identity, it agreed to trust a door the bank holds. The move keeps it but bounds it, named on the federation runbook, scoped to the bank’s own users, and drawn on the graph as the bank’s edge rather than the provider’s floor, so nobody mistakes a customer’s Microsoft for the provider’s.

The bait on someone else’s shelf

The deception layer seeds canary tokens, honeydocs that scream when opened, and some of them live across SharePoint, which is Microsoft’s. They are detection assets, not production, so losing the platform loses tripwires and not the estate. A US platform holding its tripwires is a line in the notes, to be kept knowingly or moved to bait it hosts itself.

The board

   Golem Trust's own                     the customer's edge

   Keycloak (self-hosted) ──────────────► trusts: Royal Bank ADFS (Microsoft, the bank's)
        │                                 detection bait: some on SharePoint (Microsoft)
   staff and services

The identity provider its own and staying so, the one Microsoft edge named as the customer’s and bounded at the federation line, and the detection bait on a US platform written down as a choice rather than left as a surprise.

What could go wrong?

  • The Royal Bank’s Microsoft has an outage, and the bank’s users cannot federate in, while Golem Trust’s own staff and services, who do not go through that door, are unaffected.

  • The SharePoint honeydocs go with a Microsoft account change, and it loses tripwires it had come to rely on without noticing they were on someone else’s shelf.

  • A federation trust is scoped too broadly and the customer’s edge becomes a way into more than the customer’s own corner, which is why the runbook pins the scope.


Agnes Nitt carries a second self, Perdita, in the one head, and has never yet let the wrong one answer to her name.