[{"content":" The IAM architect # Identity is rarely the most visible part of a system. Yet it determines who can access what, how applications trust one another and what happens when a user journey breaks. That intersection of security, user experience and architecture is what interests me.\nI work with IAM, SSO and Keycloak because solid identity foundations make products safer, but also easier to evolve and operate.\nThe consultant # I enjoy concrete problems: a platform that is hard to evolve, an integration that will not scale, authentication journeys that have become too complex, or teams that need to regain control of their IAM.\nMy role is to bring clarity back to these systems, then help teams build a solution they understand, can maintain and can trust.\nThe engineer # I stay close to the code and to operations. Keycloak, identity protocols, cloud, Kubernetes and automation are the tools I use to turn an architecture into a platform people can actually run.\nI favour solutions that are explicit, documented and testable: solutions that hold up through change, incidents and time.\nThe open-source contributor # The projects on this site are extensions of questions I encounter in the field. They let me explore ideas, make certain problems easier to test and share work that may be useful to other teams.\nI also contribute to the Keycloak project and publish technical notes on my blog.\nTo discuss identity, Keycloak or a concrete security challenge, get in touch.\n","externalUrl":null,"permalink":"/about/","section":"Identity at scale. Security by design.","summary":"A few words about my work, how I think about identity and what I share here.","title":"About me","type":"page"},{"content":" 6+\nYears in IAM\nFrom architecture and integration to security, upgrades and operations. 80M+\nUsers served\nAcross large-scale workforce and customer identity platforms. 4\nIndustry sectors\nHealthcare, financial services, public sector and retail. IAM expertise, from strategy to operations # I work on critical, multi-entity and multi-cloud environments, combining Keycloak, SSO/CIAM, Kubernetes, cloud security and DevSecOps practices.\nIAM architecture \u0026amp; strategy Audit existing platforms, define IAM, SSO and CIAM targets, prepare migration roadmaps and support technical decisions. Build, integration \u0026amp; industrialisation Integrate Keycloak and identity federation, automate deployments, and build secure, observable platforms on Kubernetes and OpenShift. Keycloak expertise \u0026amp; operations Harden configurations, develop extensions, investigate incidents, support upgrades and transfer knowledge to internal teams. Projects built for identity platforms # Tools designed to make identity journeys more reliable, test their resilience and simplify access management.\nKeycloak Access Requests A lightweight Keycloak extension for self-service access requests, approval, provisioning and audit. Explore project IAM Chaos An IAM and CIAM chaos-engineering and acceptance test suite for identity lifecycles, synchronisation resilience and multi-provider testing. Explore project Identity Multiplexer A secure, lightweight sidecar proxy for isolating multiple IdP sessions behind a single SSO domain. Explore project I also share technical notes on IAM, Keycloak, Linux and defensive security on my blog.\n","externalUrl":null,"permalink":"/","section":"Identity at scale. Security by design.","summary":"","title":"Identity at scale. Security by design.","type":"page"},{"content":"This page records selected contributions I make to the Keycloak project.\nCVE-2026-19608 # Contributed to the fix for authorization vulnerability CVE-2026-19608, including regression tests. Merged PR #51966.\n","externalUrl":null,"permalink":"/projects/keycloak/","section":"Projects","summary":"A record of upstream contributions to the Keycloak project.","title":"Keycloak contributions","type":"projects"},{"content":" 4nass/keycloak-access-requests Lightweight Keycloak extension for self-service access requests, approval, provisioning, and audit. Java 0 0 4nass/iam-chaos An IAM/CIAM chaos engineering and acceptance test suite for identity lifecycle, synchronization resilience, edge cases, and multi-provider testing. Python 0 0 4nass/idmux-proxy Secure and lightweight sidecar proxy for multiple IdP sessions behind one SSO domain. Go 0 0 4nass/ai-platform Personal AI software-engineering control plane for context, provider routing, token budgets, isolated Git worktrees, approvals, audit and REST/SSE. Python 0 0 ","externalUrl":null,"permalink":"/projects/","section":"Projects","summary":"A selection of personal projects, tools and technical experiments.","title":"Projects","type":"projects"}]