The Internet has become exceptionally good at recognizing accounts. Every major service can distinguish one login from another. Networks can evaluate device posture. Identity providers can assert attributes. Applications can assign roles and permissions.
Yet the person behind those accounts remains fragmented.
Your bank knows one version of you. Your employer knows another. Your mobile carrier, government, cloud provider, social platforms, and connected devices each maintain separate relationships with partial context. None of them represents a durable Internet presence that is truly yours.
The Internet recognizes credentials, sessions, devices, and accounts. It does not natively recognize the person moving between them.
The Internet has a blind spot
Digital identity is usually discussed as an authentication problem: prove possession of a password, key, token, certificate, or biometric. Authentication matters, but it answers only one narrow question—whether a claimant can satisfy a particular system's requirements at a particular moment.
It does not create continuity across networks, applications, organizations, and jurisdictions. That continuity is reconstructed repeatedly by every service provider, often through centralized accounts and duplicated personal data.
Identity is not portable
A person can move physically while remaining the same person. Their Internet presence does not move with the same continuity. It is recreated at each boundary.
Change employers and one digital identity disappears while another is issued. Change devices and trust must be rebuilt. Move between countries, providers, or networks and policy context shifts again. Even strong federated identity usually remains anchored to an institution that controls the identifier and the relationship.
Portability therefore means more than logging into multiple applications with one account. A genuinely portable presence would need to preserve continuity without forcing every relying party to depend on one permanent authority.
The Internet was built around devices
This limitation is not surprising. Internet architecture began by connecting machines and routing packets. Human identity was added later at higher layers through directories, accounts, credentials, certificates, and application-specific profiles.
Those mechanisms solve important problems. Atlas does not assume they should be replaced. The research asks whether they can be organized around a missing layer: a person-controlled Internet presence capable of forming bounded, revocable trust relationships with existing systems.
What if we started with the person?
A Personal Internet Presence would not be a universal public identifier and should not become a global tracking mechanism. It would be a controlled foundation from which a person establishes different relationships for different contexts.
A bank may need verified legal identity. An employer may need role and device posture. A public forum may need only proof that one participant is not operating thousands of automated accounts. A private service may need no civil identity at all.
The person remains the persistent point of reference while each relationship receives only the information necessary for its purpose.
Beyond authentication
The distinction matters because authentication is an event. Presence is continuity.
A useful person-controlled layer would need to support more than login. It would need mechanisms for establishing relationships, presenting limited context, rotating credentials, recovering control, revoking access, moving between networks, and preserving privacy across unrelated domains.
It would also need to fail safely. A compromised provider, device, or credential must not become a compromise of the person's entire digital life.
A foundation, not another platform
Atlas Identity is not intended to become another identity provider, social network, wallet, application platform, or centralized database of people.
The stronger architectural direction is a layer that works with what already exists: public-key infrastructure, passkeys, verifiable credentials, device attestation, policy engines, network controls, secure hardware, privacy-preserving proofs, and federated trust.
The research challenge is not inventing every component. It is determining whether the components can form a coherent architecture around the individual without creating a new centre of control.
Why publish the research openly?
A proposal at this scale should not be developed behind closed doors. Networking, security, identity, cloud, privacy, governance, standards, and abuse prevention each expose different failure modes.
Atlas therefore treats criticism as part of the design process. The objective is not to prove the thesis correct. The objective is to identify where it fails, what already exists, what assumptions are wrong, and what risks have not yet been considered.
An invitation
The Internet may not need a new person-controlled layer. Existing standards may already provide most of it. The concept may introduce unacceptable privacy, governance, operational, or security risks.
Those possibilities are precisely why the work should be examined publicly.
Atlas Identity begins with one observation: the Internet is highly capable of recognizing accounts, devices, networks, and institutions, but the individual remains fragmented across all of them.
The question is whether that fragmentation is unavoidable—or whether it reflects a missing architectural layer.
Continue the research
Read Atlas Paper 001: The Missing Layer of the Internet
The paper develops the technical thesis behind Personal Internet Presence and identifies the assumptions requiring review.
Read Atlas Paper 001