Published: 25/08/2026

Building interoperable digital identity systems
Identity ecosystems are evolving beyond humans. In the modern world, organizations, machines, and products increasingly need ways to establish trust and verify themselves. Some frameworks and pilots are emerging, but the architecture is far from settled. As these ecosystems take shape, the challenge ahead is ensuring they can work together.
Summary
- Digital identity is rapidly expanding beyond humans to include organizations, machines, and products.
- As new identity frameworks are established around divergent priorities, it’s important that systems are designed for interoperability from the outset.
- Decentralized infrastructure, which has already proven its scalability for human identity, can provide the foundation for all entity types –despite their divergent objectives.
The word identity carries many connotations. On a personal level, it captures the essence of our being – who we are, our values, and the experiences that shape us. On a deeper level, it is intertwined with notions of gender, social class, and ethnicity. Answering the question of “who we are” is a complex matter each of us must answer individually.
Setting aside this philosophical reflection, the concept of identity can be considered in more practical terms. Identity comprises both mutable and immutable attributes – your physical appearance may change over time, but your date of birth will always be the same. Identity also encompasses different levels of assurance depending on who issued it: a government-issued passport carries more weight than a gym membership card. Then there’s the distinction between the identity itself, identifiers (such as a social security number), and the acts of identification and verification. Identity can be delegated – think of a parent booking flights on behalf of children, or a manager signing contracts for a company. And in everyday transactions, identity functions as attestation, proving “I am who I say I am” to establish trust with another party.
In most cases, establishing personal identity usually comes down to practical characteristics, such as name, date of birth, and residential address, easily verified by the credentials we carry: passports, driver’s licenses, identity cards. But what happens when we translate all of this into the digital world?
“Digital identity ecosystems must account for all of the complexities of the real world, which amplifies the challenge considerably,” says Robert Heinze, Director of Technology & Innovation Management at G+D. Building these ecosystems requires establishing frameworks that define how identities are issued, verified, and trusted in the digital world. However, the challenge becomes even more complex when you consider how identity ecosystems are evolving beyond humans and organizations to include entities such as machines and products.
Open a rental car door with your smartphone, and a machine must verify your identity to start the engine. Purchase a battery-powered device, and, by 2027, that battery will carry its own digital passport with credentials about its origin, composition, and carbon footprint. Submit an ESG report, and your company must authenticate itself as a legal entity while aggregating data from sensors, supply chain partners, and products – each requiring its own form of identification.

Tackling divergent goals with shared foundations
As these new identity ecosystems evolve, they will pursue fundamentally different, even contradictory, objectives. Human identity systems prioritize privacy and confidentiality. Product passports demand transparency and traceability. Organizations require both. Adding to this complexity is the fact that each entity may function as issuer, holder, or verifier depending on the context. Yet a unified technical foundation could provide an answer. Decentralized infrastructure – in the form of verifiable credentials, digital wallets, and cryptographic presentation – has already proven a strong and flexible base for scaling human identities. It is a reasonable assumption that this could also provide a common foundation across the other entity types.
Regulation is also providing momentum. Legislation such as the “EU Digital Identity Wallet” – requiring member states to issue wallets by 2026 – is creating an interoperable framework for human digital identity across 27 member states. The Digital Product Passport will follow in 2027, establishing similar requirements for products such as batteries. Early organizational identity initiatives, such as GLEIF’s verifiable Legal Entity Identifier (vLEI), are also taking shape.
As these and more initiatives develop, the challenge (and opportunity) for stakeholders is understanding how to make them work together.
“Each entity type is developing identity frameworks tailored to specific needs,” says Heinze. “But what we can already foresee is that all of these identities – and their owners – will meet even in very basic use cases. If these systems aren’t designed to work together, even simple everyday transactions will become unnecessarily complex.”
When entities interact
Consider the example of an employee (human) renting a car for a business trip. At the rental desk, the employee presents their driver’s license and corporate credentials (organization), which the rental agent verifies. Once behind the wheel, the connected car (machine) authenticates with the rental company’s systems and the employee’s smartphone to start the engine.
When returned, the car’s emissions data needs to flow into the employer’s ESG reporting. The vehicle records and signs the emissions data, the employee confirms the trip, and then the data is securely transmitted to the company’s systems. Throughout this transaction, each entity adopts different roles – acting as both holder and verifier of credentials at different points in the transaction. The more seamlessly the different identity systems can authenticate and verify one another, the more frictionless the experience for all parties.
Achieving that seamlessness in practice requires solving several interconnected challenges.
Digital identity ecosystems must account for all of the complexities of the real world, which amplifies the challenge considerably.
Firstly, different entity types operate under vastly different security requirements. For example, government-issued human identities demand a much higher threshold of security than a commercial tracking system. There is also the question of governance: who sets the rules, resolves disputes, and enforces standards across entity types with different regulatory oversight?
Then there’s the binding challenge: how do you securely link a digital identity to a physical object and verify in the real world that they match? A digital product passport must be bound to a specific battery in a way that resists tampering and counterfeiting. Human credentials face similar challenges – a passport must work for both digital authentication and physical presentation at a border, with biometrics providing the binding between the document and the person. As identity systems expand to machines and products, this challenge of creating trustworthy physical-to-digital bindings will need to be solved.
Identity types also shift depending on context (a car can be a machine or product), exist in hierarchies (a company owns machines containing products), and a single entity may require multiple identity types simultaneously.

Designing digital identity systems that work together
Addressing these challenges requires coordination across technical, regulatory, and governance domains. To provide a road map forward, G+D, in collaboration with Veridos, has developed a conceptual framework that serves as both an analysis and a call to action for industry stakeholders.
The framework puts forward three strategies. The first is a set of shared, cross-entity standards that let systems communicate without forcing them into uniformity. The second is decentralized frameworks flexible enough to accommodate centralized elements where regulation or risk demands them. The third is technical “bridges” that allow a credential issued in one system to be verified in another.
Share this article
Don’t miss out on the latest articles in G+D SPOTLIGHT: by subscribing to our newsletter, you’ll be kept up to date on latest trends, ideas, and technical innovations – straight to your inbox every month.

