Release cadence across four business lines and three tools
We keep “shipped”, “in progress” and “planned” clearly separated. Shipped items do not get reversed — that is part of our public commitment.
UIAM roadmap
Unified identity & access management
v1.0ReleasedCore kernel- Identity kernel and multi-tenant isolation
- OAuth 2.1 / OIDC authorization server
- RBAC roles and permission management
- MySQL / PostgreSQL dual dialects
v1.2ReleasedAgent IAM- MACHINE principal modelling and service accounts
- RFC 8693 delegation chains with multi-hop propagation
- MCP endpoints and tool-level authorization
- Agent call quotas and rate limits
v1.4In developmentGovernance hardening- Real-time permission-change push (no more waiting for the next login)
- Audit event stream integration with SIEM
- Zero-downtime system JWT key rotation
- A programmable policy engine
v2.0PlannedFederation & policy- Cross-tenant federated identity
- An ABAC policy language
- Cross-border identity data compliance policies
- A third-party application marketplace
How the roadmap is decided
We do not promise features by quarter; what comes next is decided by kernel stability.
Data model and boundary rules come first. Only once the kernel is stable do we dare move fast on the layers above.
Audit, quotas and permission refinement — the capabilities that demo poorly but must exist — are scheduled early.
Interaction and visualisation come after kernel and governance — no building on sand.
Open APIs, plugins and a marketplace come last, and only once the contracts are stable.
What it took to get here
The roadmap looks forward, the timeline looks back. Every node is backed by a deliverable.
Zhenbei’s first business line was unified identity. The starting point was concrete: customers ran several business systems, each maintaining its own accounts, with mismatched permission semantics and no audit view to show. We started from the identity kernel, getting OAuth 2.1 / OIDC, tenant isolation and fine-grained authorization right.
As agents entered enterprise systems, the existing identity model could not hold them: agents worked with human tokens, and incidents could not be attributed. So machine principals, delegation chains, multi-hop propagation and MCP tool authorization became first-class capabilities of the kernel.
Beyond identity, customers raised needs in private-domain operations, online learning and AI applications — all sharing the same underlying judgements: where data should live, and who should guard the boundary. Four business lines took shape, in different languages but under one engineering standard.
Once products ran in production, the real pressure came from operations and iteration. We did two structural rebuilds: Unilearning folded 6 microservices into 1 modular monolith, and Uniscrm rebuilt customer relationships from “friends inside an employee’s WeChat” into a company asset that can be inherited.
Across four business lines in production we accumulated a set of internal tools sharing one trait: kernel separated from shell, with AI treated as a first-class citizen. We polished them into products — running internally first is what made us willing to ship them.
Hand the complexity of identity, agents and private domain to one governable kernel
Whether you are replacing an existing IAM, building an agent platform, or trying to make private-domain operations actually work — start with a 30-minute architecture call. We will first judge whether this is the kind of problem we are good at, and say so plainly if it is not.