Governments spend billions securing identity databases.
Encryption. Multi-factor authentication. Biometrics. Zero-trust architectures. Each breach triggers another layer of security, another vendor, another system that citizens must navigate.
And yet: trust is declining. Fraud is rising. Citizens still wait weeks for services that should be instant.
Here’s why: we’re solving for the wrong problem.
We’ve framed digital identity as a security problem. What if it’s actually an infrastructure problem we’re trying to solve with security tools?
The Mental Model Shift: Infrastructure vs Security
Think about electricity for a moment.
You don’t secure electricity by building a separate power plant for every building. You build a grid—shared infrastructure that every building plugs into. The grid itself is secured, but the architecture is about access.
Now think about how governments handle digital identity today.
Every agency builds its own identity verification system. Every service creates its own database. Every citizen interaction requires proving “I am who I say I am” from scratch.
This isn’t an electricity grid. This is every building running its own generator. We’re solving a local problem (this agency needs to verify identity) while missing the global opportunity (citizens need portable trust across all services).
The Inversion Exercise: What Guarantees Failure?
Let’s invert the problem.
If you wanted to guarantee that digital government fails, what would you do?
1. Make citizens prove their identity separately for every service
2. Store copies of their data in hundreds of siloed databases
3. Require them to remember dozens of passwords for government platforms
4. Make each agency responsible for verifying the same person independently
5. Ensure no service can talk to any other service
Look familiar?
That’s not a cynical description of bad government. That’s the actual architecture of most digital government systems today.
When you invert the problem, the solution becomes obvious: stop building identity systems and start building identity infrastructure.
First Principles: What Is Identity Actually For?
Let’s go back to basics. What is identity actually for? What job does digital identity do in government?
Answer: Identity establishes trust between a citizen and a service.{
That’s it. Not security (that’s a constraint). Not databases (that’s an implementation). Not compliance (that’s a requirement).
The core function is: create trust once, use it everywhere.
From first principles:
- Trust should be established once, not repeatedly
- Identity should be portable, not siloed
- Verification should be infrastructure, not per-service overhead
- Citizens should own their credentials, not surrender copies to every agency
Now ask: does your current system do any of this?
The Infrastructure Reframe: What Changes
When you shift from “security problem” to “infrastructure opportunity,” everything changes:
Security framing asks:
- How do we protect this database?
- How do we prevent unauthorized access?
- How do we comply with data protection laws?
Infrastructure framing asks:
- How do we verify identity once and reuse it everywhere?
- How do we make trust portable across services?
- How do we reduce citizen friction while increasing security?
Security framing optimizes for protection. Infrastructure framing optimizes for utility—with security as a design constraint, not the objective.
It’s the difference between building a fortress and building a highway system. Both need to be secure, but the architectures are entirely different.
The Evidence: What Happens When You Build Infrastructure
Here’s what changes when governments treat identity as infrastructure instead of a security problem:
Before (Security Model):
- Citizen proves identity to 15-30 different agencies
- Each agency maintains separate databases with copies of the same data
- New services take 12-18 months to deploy (identity integration is the bottleneck)
- Fraud prevention requires each agency to verify independently
- Citizens abandon processes due to complexity
After (Infrastructure Model):
- Citizen verifies once, accesses 120+ services
- Identity credentials are portable and citizen-owned
- New services deploy in 4-6 weeks (plug into existing infrastructure)
- Fraud prevention happens at the infrastructure layer
- Service completion rates jump 3-5x
This isn’t theory. These are metrics from deployed systems in Argentina, Mexico, and Colombia serving 8M+ citizens.
The infrastructure model doesn’t reduce security—it moves security to the right layer while simultaneously solving the utility problem.
The Strategic Implications: Why This Matters Now
Every government is digitizing. The question isn’t whether to build digital identity—it’s what architecture to choose.
Security architecture: Each agency builds and secures its own system. Incremental progress. Compounding complexity.
Infrastructure architecture: Build shared verification layer once. Every new service gets faster, not harder.
The gap between these two approaches compounds over time.
In Year 1, the difference is modest—maybe a few services deployed faster.
In Year 5, one government has unlocked 100+ digital services. The other is still integrating systems one by one.
In Year 10, it’s not even comparable. One has infrastructure that makes new services trivial. The other is trapped in technical debt.
The Hard Truth: What This Requires
Treating identity as infrastructure requires something uncomfortable: architectural thinking, not vendor solutions.
You can’t buy infrastructure from a vendor and bolt it onto existing systems. Infrastructure is a design decision that affects everything built on top of it.
This is why governments struggle. It’s easier to add another security layer than to rethink the architecture. It’s easier to solve the local problem than to step back and solve the global one.
But easy and right rarely align.
The Decision Point: What To Ask
If you’re leading digital transformation, here’s the diagnostic:
Question 1: When you deploy a new digital service, does it get easier or harder than the last one?
- Easier = you have infrastructure
- Harder = you’re accumulating technical debt
Question 2: Can a citizen verify their identity once and access all your services?
- Yes = infrastructure model
- No = security model with utility problems
Question 3: Are you building systems or architecture?
- Systems = solving local problems
- Architecture = solving the global problem once
Your answers reveal which path you’re on.
The Category: Name It
This shift from security problem to infrastructure opportunity is what defines reusable identity infrastructure as a category.
Not better identity verification (security framing).
Not stronger authentication (security framing).
Not compliance-friendly databases (security framing).
Reusable identity infrastructure: The architectural layer that lets citizens verify once and access everything.
The category isn’t defined by technology (blockchain, biometrics, zero-knowledge proofs). It’s defined by the problem it solves: making trust portable instead of repeatedly proving the same thing.
The Call: What’s Next
The governments winning on digital service delivery made an architectural decision:
They stopped treating identity as 47 different security problems and started treating it as one infrastructure opportunity.
If you’re still adding security layers to fragmented systems, you’re optimizing locally while losing globally.
The question isn’t whether to secure identity. It’s whether to build infrastructure that makes trust reusable.
One approach leads to incremental improvement on a fundamentally limited architecture.
The other leads to compounding returns where each new service is easier than the last.
Which path is your government on?
Quick Reads This Week
📄 Digital Public Transformation in Latin America - Latest thinking on digital identity in Latin America
🎙️ Sovra Podcast #04 — Martín Güemes: Digital Identity as Public Policy in Salta, Argentina - How Salta, Argentina is building reusable infrastructure
🔗 W3C Verifiable Credentials Data Model - The open standard for digital credentials and portable identity
🌐 eIDAS Regulation (EU) - How Europe is building interoperable identity (benchmark for LATAM)
P.S. Forward this to someone rethinking digital government architecture.






