← Back to The Backroom
video|Sybrin Game Changers

Is Self Sovereign Identity Going Exponential?

AWS Head of EC2 Engineering Andrew Baker and a surprise guest from the Sovrin Foundation on whether self sovereign identity can fix digital identity for good.

Colin Iles·
Share

Chapters


Key Takeaways

AWS's Andrew Baker and Sovrin Foundation board member Lohan Spies on whether self sovereign identity can finally fix digital identity: how issuers, holders, and verifiers work, why the Sovrin ledger is public but permissioned, and why just-in-time credential sharing could replace passwords and stored customer data for good.

  • Andrew Baker estimates 30 to 40 percent of historical call centre volume was password reset requests, a process both costly to service and prone to fraud.
  • The Sovrin Foundation's open source technology started with commercial venture Evernym in 2015 to 2016 and became Hyperledger Indy; the Sovrin network has run for five years and is described as the largest SSI-based network in the world.
  • In South Africa, only two organisations hold transaction endorser (write access) status on the Sovrin network: Absa and Lohan Spies himself.
  • No private data is ever written to the Sovrin blockchain, only a distributed digital identity and a signing key; actual credentials stay with the holder in their wallet.
  • During South Africa's DebiCheck rollout, some banks struggled to reach even 50 percent of customers through stored contact details, illustrating the case for just-in-time identity over stored point-in-time snapshots.
  • Andrew Baker predicted a major tech platform would offer self sovereign identity login, alongside Google and Facebook single sign-on, within the following year.
6 min read

In this Sybrin Game Changers conversation, AWS Head of EC2 Engineering Andrew Baker (newly appointed at the time of the call, having just left a decade at Barclays and a stint as CTO at ABSA) joins Colin Iles alongside a surprise guest, Sovrin Foundation board member Lohan Spies, to ask whether self sovereign identity can fix digital identity for good. Baker frames the current model as fundamentally broken: 30 to 40 percent of historical call centre volume was password resets, and "a fraudster will also have forgotten it," while Spies explains how the nonprofit Sovrin Foundation built a public, permissioned blockchain to let individuals hold and control their own credentials.

Why passwords and federated logins are the problem, not the fix

Baker opens by grounding the case for self sovereign identity in real operational pain rather than theory. He recalls that roughly 30 to 40 percent of call centre volume at his former employer was people asking for a username or password reset, a process that is both expensive to service and easy to exploit, since "the person who's calling you to get the password reset, there's a high likelihood that that's not actually the person who owns the account." He points to Have I Been Pwned as evidence that federated identity providers like Google and Facebook have leaked credentials at scale, and to WhatsApp's data-sharing change with Facebook as a moment that made people uneasy about handing over their identity to a platform. His summary of the alternative: "the person and the individual, for the first time ever, actually owns their own credentials, and that is a game changer."

How self sovereign identity actually works: issuers, holders, and verifiers

Baker explains the mechanics using Colin as the example holder. Home Affairs, the issuer, issues a verifiable Home Affairs ID credential into Colin's digital wallet. When a bank (the verifier) needs to confirm Colin has a valid ID, it requests a proof, which Colin's wallet returns and the bank checks cryptographically against a public blockchain ledger. Critically, Baker stresses that no private data is ever written to the blockchain, only a distributed digital identity and a signing key: "the data stays with the holder in the wallet." Selective disclosure and zero knowledge proofs then let a holder prove an attribute, such as being over 18 or earning above a threshold, without revealing the underlying raw data.

Upcoming Virtual Event

Financing Africa's $45bn Used-Car Market

Thursday, 6 August 2026

With Etop Ikpe, Autochek

Register

The Sovrin story: from a commercial startup to a nonprofit global ledger

Lohan Spies, introduced partway through the call as the Sovrin Foundation's ex officio board member and chair of its Steward Council, traces the technology back to Evernym, a commercial venture that open-sourced its self sovereign identity code base in 2015 and 2016. That code became Hyperledger Indy, the underlying distributed ledger technology, while Evernym donated the framework to the newly formed nonprofit Sovrin Foundation so that governance and commercial interest would sit separately. Spies says the network has run for five years and is the largest SSI-based network in the world, operating a staging net and a production Sovrin MainNet. Unlike Bitcoin or Ethereum, the Sovrin ledger is public but permissioned: anyone can apply to become a "transaction endorser" able to write to the network, but a governance process controls who qualifies, similar in spirit to how ICANN governs internet naming. In South Africa, Spies says only two organisations currently hold that status: Absa and himself.

Just-in-time identity versus today's point-in-time snapshots

Responding to a question about whether self sovereign identity means bulk data sharing or one-off transactional requests, Baker and Spies both describe a shift from stockpiling customer data to requesting it fresh each time it's needed. Baker cites South Africa's DebiCheck initiative, where some banks struggled to reach even 50 percent of customers through stored contact details because people move address, change phone numbers, and change email over the years a bank account stays open. Spies adds that today's identity model is "point-in-time," meaning stored data can be outdated within days or weeks, whereas a just-in-time model lets an institution request current data directly from the holder's wallet, paired with selective disclosure so the holder controls exactly what's shared and in what format.

Revocation, authentication, and the end of usernames and passwords

Asked whether an issuer can revoke a credential, for example if Home Affairs is hacked and needs to reissue IDs, Spies confirms revocation is built into the protocol: a revoked credential remains verifiable as having been issued, but carries a flag showing its revoked status, leaving the verifier to decide how to treat it. On authentication more broadly, Spies says self sovereign identity can eliminate usernames and passwords entirely, because authentication happens peer to peer between the holder's wallet and the verifier rather than through a centralised federated identity provider. Baker adds that because a person holds many separate DIDs (digital IDs) rather than one universal identifier like an email address, different services cannot correlate a person's activity across trust boundaries unless the holder chooses to allow it.

Jump to a section of the interview

All links open the full recording on YouTube.

Is self sovereign identity the same as Bitcoin or Ethereum?

No. Baker explains that Sovrin does not use Bitcoin's proof of work consensus, so there's no mining and no associated energy cost. More importantly, the Sovrin ledger is public but permissioned rather than permissionless: writing to the network requires becoming a vetted "transaction endorser" through a governance process, unlike Bitcoin's fully decentralised, ungoverned model. Spies adds that this governance layer, closer in spirit to how ICANN oversees internet naming, is precisely what has let governments and corporates buy into Sovrin, since institutions can read and understand the governance framework rather than trusting a purely leaderless network.

When will ordinary consumers actually see self sovereign identity at login?

Baker predicts a major tech platform will offer self sovereign identity as a login option, alongside Google and Facebook single sign-on, as soon as the year following the call, pointing to early movement from companies like Microsoft and IBM. He argues South Africa is unusually well positioned because Home Affairs already exposes an API to verify identity documents against biometric data, meaning strong verified credentials could scale into wallets quickly. Spies points to global momentum already underway, including the IATA Travel Pass for verifying COVID vaccination or test status with airlines, and adoption interest from Germany, the European Union, and Canada.

Does self sovereign identity mean all my personal data is stored on a blockchain?

No. Baker is explicit that the only things written to the Sovrin blockchain are a distributed digital identity and a signing key, never the underlying private data itself. Actual credential data, such as a date of birth or an ID number, stays with the holder in their own wallet and is only shared directly with a verifier when requested, using cryptographic proofs rather than a shared database.


CI

Colin Iles

Colin hosts invitation-only executive roundtables and founder interviews across Africa's tech and financial services sectors. Learn more

The Backroom

Get conversations with senior leaders delivered to your inbox.

For B2B Sponsors

Invested in webinars but disappointed with the conversions?

We build rooms that senior decision makers actually show up to. You get the pipeline.

Book a strategy call