Two apps, split by plane.
A phone is an enforcement point and a place to approve from — never a control plane. The phone approves; the brain decides; the edge enforces. That rule is why there are two apps here instead of one with a role switch in it.
An app is a form factor, never the control plane.
Two apps, compiled apart — not one binary with a role switch in it. Each extends a different plane, and the boundary between them is enforced on the server, not in the client.
Helix Authenticator
Carries
- Identity hub
- MFA — N-factor, approving your own sign-ins
- Wallet / Certificates (DID & verifiable credentials)
- Helix Messages
- Your own devices’ posture and sessions
- Approvals, recovery and consent
Does not carry
- Any estate
- Any other person’s data
- The control plane
Helix Command
Carries
- The unified approvals inbox — containment, certificates, step-up, approved with the operator’s own MFA
- Critical alerts and on-call
- Read-only triage context
- Verified operator comms
Does not carry
- Policy authoring
- Detection or conductor configuration
- SOC orchestration — Timeline, cases, posture, fleet
The control plane — decide, author policy, orchestrate — lives in the brain and the web Console, and is never exposed in an app. The client is never the security boundary: entitlement, role, tenancy and the conductor gate are all resolved server-side, so a copied or modified client is powerless rather than dangerous. That is why the split is two binaries and not a setting.
See your environment as one Timeline.
A 30-minute walkthrough on your data — self-hosted or on Helix Counter Cloud. Every finding cites the regime that governs it.