HomeProduct roadmap
Roadmap

Release cadence across four business lines and three tools

We keep “shipped”, “in progress” and “planned” clearly separated. Shipped items do not get reversed — that is part of our public commitment.

UIAM roadmap

Unified identity & access management

View full details
v1.0ReleasedCore kernel
  • Identity kernel and multi-tenant isolation
  • OAuth 2.1 / OIDC authorization server
  • RBAC roles and permission management
  • MySQL / PostgreSQL dual dialects
v1.2ReleasedAgent IAM
  • MACHINE principal modelling and service accounts
  • RFC 8693 delegation chains with multi-hop propagation
  • MCP endpoints and tool-level authorization
  • Agent call quotas and rate limits
v1.4In developmentGovernance hardening
  • Real-time permission-change push (no more waiting for the next login)
  • Audit event stream integration with SIEM
  • Zero-downtime system JWT key rotation
  • A programmable policy engine
v2.0PlannedFederation & policy
  • Cross-tenant federated identity
  • An ABAC policy language
  • Cross-border identity data compliance policies
  • A third-party application marketplace
How We Plan

How the roadmap is decided

We do not promise features by quarter; what comes next is decided by kernel stability.

01
Kernel first

Data model and boundary rules come first. Only once the kernel is stable do we dare move fast on the layers above.

02
Then governance

Audit, quotas and permission refinement — the capabilities that demo poorly but must exist — are scheduled early.

03
Then experience

Interaction and visualisation come after kernel and governance — no building on sand.

04
Ecosystem last

Open APIs, plugins and a marketplace come last, and only once the contracts are stable.

History

What it took to get here

The roadmap looks forward, the timeline looks back. Every node is backed by a deliverable.

StartUIAM
It began with one identity system

Zhenbei’s first business line was unified identity. The starting point was concrete: customers ran several business systems, each maintaining its own accounts, with mismatched permission semantics and no audit view to show. We started from the identity kernel, getting OAuth 2.1 / OIDC, tenant isolation and fine-grained authorization right.

Identity kernel and tenant isolation
OAuth 2.1 / OIDC authorization server
RBAC roles plus data permissions on two tracks
Homogeneous MySQL / PostgreSQL dialects
ExpansionUIAM · Agent IAM
The identity boundary moved from people to AI

As agents entered enterprise systems, the existing identity model could not hold them: agents worked with human tokens, and incidents could not be attributed. So machine principals, delegation chains, multi-hop propagation and MCP tool authorization became first-class capabilities of the kernel.

MACHINE principals and service account modelling
RFC 8693 delegation chains with permission intersection
agent_tools registry and tool-level authorization
Agent call quotas and end-to-end audit
FormationFour business lines
One business line became four

Beyond identity, customers raised needs in private-domain operations, online learning and AI applications — all sharing the same underlying judgements: where data should live, and who should guard the boundary. Four business lines took shape, in different languages but under one engineering standard.

Uniscrm WeCom SCRM (16 modules / 132 endpoints)
Uniclaw multi-tenant AI agent platform (25 modules / 19 tools)
Unilearning online learning platform (8 domains / modular monolith)
All four lines sharing the UIAM identity kernel
RebuildUnilearning · Uniscrm
Turning “good enough” into “holds up”

Once products ran in production, the real pressure came from operations and iteration. We did two structural rebuilds: Unilearning folded 6 microservices into 1 modular monolith, and Uniscrm rebuilt customer relationships from “friends inside an employee’s WeChat” into a company asset that can be inherited.

Unilearning: 6 microservices → 1 binary, internal wall enforced by the compiler
Uniscrm: customer assetisation, conversation archiving and channel attribution
Unilearning: legacy-import migration preserving IDs and passwords
Migration proceeds domain by domain, each independently rollback-able
NowToolkit
The toolkit: built for ourselves, used by ourselves, then shipped

Across four business lines in production we accumulated a set of internal tools sharing one trait: kernel separated from shell, with AI treated as a first-class citizen. We polished them into products — running internally first is what made us willing to ship them.

legdger encrypted local-first ledger (iOS / macOS / CLI)
NewTool Rust algorithm kernel toolbox (desktop / CLI / WASM / MCP)
pxc capture proxy and team collaboration (Go kernel + three shells)
Tools and business lines under one engineering standard
Get in touch

Hand the complexity of identity, agents and private domain to one governable kernel

Whether you are replacing an existing IAM, building an agent platform, or trying to make private-domain operations actually work — start with a 30-minute architecture call. We will first judge whether this is the kind of problem we are good at, and say so plainly if it is not.