BRIDGE: Autonomous Digital Identity Governance in Non-Federated Environments
Author · Defended in 2026
Master's thesis, 3iACCentral Africa Institute of Computer Engineering, an institute of IUC. · Institut Universitaire de la Côte (IUC), 3ILComputer engineering cycle at IUC, within the 3iAC institute. Engineering Cycle
Hybrid identity reconciliation engine (deterministic, probabilistic, LLM/RAG assistance on residual cases), with a Business Rules Engine and differential audit (Event Sourcing/CQRS). Deployed at MTN Cameroon: 100+ sources, 150,000+ digital identities, 0.995 precision and 0.999 recall on a 5,000-identity annotated sample, benchmarked against Splink.
Details
- Problem: governing digital identities in a non-federated environment, with no shared identifier or centralized directory. This is the MTN Cameroon case (100+ business applications, 2.6M records, 150,000+ digital identities collected since 2022).
- Hybrid reconciliation: deterministic matching on strong identifiers, probabilistic scoring (Fellegi-Sunter-inspired) on semi-strong identifiers, and targeted large language model (LLM) assistance via a RAG architecture for ambiguous residual cases and automatic mapping discovery on new sources.
- Rules-based governance: a Business Rules Engine backed by Mandate Lists detects non-conformities (segregation of duties, dormant accounts) where no source provides reliable categorization.
- Differential audit: system state is derived from an immutable sequence of events (Event Sourcing, CQRS pattern), enabling full history reconstruction of a profile rather than a single snapshot.
- Non-intrusive architecture: a passive observer with strictly unidirectional connectivity, reading source system extractions without writing to them or imposing constraints.
- Results on a 5,000-identity annotated sample (14 representative systems): 0.995 precision, 0.999 recall, benchmarked against Splink (a reference entity-resolution library).