Skip to content
Bastyx
Roadmap

What we’re building, in the open.

Bastyx is in early access. Nothing below is generally available yet. Items move columns when their status changes, and anything that ships gets a changelog entry.

Early-access focus

Early access

What early-access teams will shape first.

  • Passwordless sign-in

    Passkeys, FIDO2 security keys and device biometrics.

  • SSH access

    Short-lived, identity-bound access with no keys on servers.

  • Workstation login

    Windows and Linux sign-in with the same identity.

  • Onboarding and offboarding

    Grant and revoke every access path in one step.

  • Device enrollment

    Bind laptops to people so policy can require a known device.

  • Audit log

    Authentication and admin events in one place.

Planned

Planned

Committed direction, after the early-access focus.

  • Role and resource policies

    Scope access by team, role and resource tag.

  • Temporary access with approvals

    Time-boxed elevated access that ends on its own.

  • Risk-based step-up

    Signals raise risk; policy decides the response.

  • Identity provider sync

    Keep your directory where it is.

  • Event export

    Stream events to your logging and SIEM stack.

  • Customer-hosted deployment

    Run the control plane in your environment.

Exploring

Exploring

Under evaluation. May change or not ship.

  • macOS login

    Passwordless sign-in for Mac workstations.

  • USB-C fingerprint reader

    Optional hardware for machines without a sensor.

  • Machine identities

    Short-lived access for CI and automation.

Changelog

What has shipped

No releases yet

The first entry will appear when early-access teams start using Bastyx. Every entry will say exactly what changed and who it’s available to.

Tell us what should come first.

Early-access teams directly influence the order of this list.