Why I'm writing this
For the better part of two decades I've watched organizations â universities, public administrations, hospitals, and mid-sized companies â hand over the core of their digital existence to a handful of vendors. Email, documents, calendars, video, identity, storage. Not because it was the best technology, but because it was the path of least resistance. The bill arrives later, in the form of lock-in, opaque data processing, and a slow erosion of the ability to decide for oneself.
This article is my vision of the sovereign digital workplace â what it is, why it matters, and how I believe we get there. It is not a product brochure. It is a roadmap, drawn in pencil, from where we stand today to the year 2055.
If you want the executive summary: sovereignty is not about rejecting cloud or AI. It is about owning the rules, the data, and the exit â and building workplaces where humans remain the authors of their own digital lives.
What "sovereign" actually means
A sovereign digital workplace has three non-negotiable properties:
- Data sovereignty â The organization (or person) controls where data lives, who can access it, and under which jurisdiction it is processed. No silent secondary use.
- Process sovereignty â The workflows, formats, and integrations are open and portable. You can leave a vendor without losing your history, your documents, or your automations.
- Infrastructure sovereignty â The stack runs on infrastructure you can inspect, audit, and replace. Open-source components, reproducible deployments, and a documented exit path from day one.
This is exactly the philosophy behind projects like openDesk (the sovereign workplace suite) and my own openDesk Edu extension that brings ILIAS, Moodle, and BigBlueButton into a self-hosted, Kubernetes-deployed stack for universities. The roadmap below scales that idea from "a suite you can host yourself" to "a workplace that thinks alongside you without owning you."
The roadmap: 2025 â 2055
I've split the next three decades into four phases. Each phase ends when its capability is mainstream, not when a calendar flips.
Phase 0 â Decouple (2025â2030)
The problem we start with: most workplaces are single-vendor estates. Microsoft 365 or Google Workspace is not just mail and docs; it is identity, compliance, automation, and institutional memory. Leaving feels impossible â which is precisely why exit strategies must be built during adoption, not after.
What gets built:
- Open core suites in production. OpenDesk, Nextcloud, and Matrix move from pilot to default for at least one critical workflow per organization.
- Exit-by-design. Every new system ships with a documented data-export and re-import contract. If you can't leave in a weekend, you don't deploy.
- Sovereign identity. Self-hosted Keycloak (SAML + OIDC) becomes the front door, replacing vendor-locked SSO.
- Reproducible infrastructure. Kubernetes + Helmfile deployments (the pattern openDesk Edu uses) become the boring default, not a heroic effort.
By 2030, the question is no longer "can we self-host?" but "why would we rent what we could own?"
Phase 1 â Federate (2030â2040)
Decoupling one org is a start. Federating many is the leap.
What gets built:
- Federation as a right. Matrix-style federation becomes the expectation for chat, conferencing, and identity. A university, a hospital, and a city administration collaborate as naturally as they email today â without a common vendor.
- Sovereign AI assistants. Locally-run, organization-specific language models (think vLLM + LiteLLM on your own GPUs) handle drafting, summarization, and routing â with zero training-data leakage to third parties.
- Composable workplaces. Teams assemble their stack from interchangeable open modules: pick your editor, your LMS, your whiteboard. Standards (OCI, ODF, ActivityPub-style protocols) keep them interoperable.
- Audit-by-default. Every action is logged to tamper-evident storage; compliance becomes a query, not an audit-nightmare.
By 2040, sovereignty is social, not just technical: organizations trust each other's infrastructure because it is verifiable.
Phase 2 â Augment (2040â2050)
Now the workplace stops being a toolbox and becomes a colleague.
What gets built:
- AI co-stewards. Persistent, locally-grounded agents maintain the infrastructure itself: capacity planning, incident response, patch orchestration â under human-authored policy and with full rollback.
- Personal sovereign agents. Each person has an agent that acts on their behalf across federated services, negotiating access, summarizing, and protecting attention â bound by personal policy, not vendor terms.
- Verifiable provenance. Every document, decision, and model output carries cryptographic provenance. You can prove where information came from and who touched it.
- Energy-aware computing. Sovereign infrastructure is also ecological infrastructure: workloads follow renewable availability; efficiency is a first-class SLA.
By 2050, the workplace anticipates, but the human still decides. Sovereignty means the agent is yours, not rented.
Phase 3 â Realize (2050â2055)
The destination, not a finish line.
- The sovereign workplace is the default for public institutions and a credible default for everyone else.
- Exit is instantaneous â data, agents, and history port in hours, not years.
- AI is a public infrastructure layer â open models, open benchmarks, independently audited, governed by multistakeholder institutions rather than quarterly earnings.
- Digital dignity is a norm: people understand their digital environment as something they own and shape, the way we (ideally) understand our homes.
The principles that survive every phase
Roadmaps are guesses; principles are load-bearing. Whatever the year, these hold:
- Open by default. If you can't read it, fork it, or leave it, it isn't sovereign.
- Exit is a feature, not a failure. Design for leaving from the first commit.
- Local first, cloud optional. Run it in your basement or in a sovereign region â same artifacts.
- Human authorship. AI accelerates decisions; it does not absolve us of making them.
- Interoperate or die. A sovereign island is just a smaller cage. Federation is the point.
What I'm doing about it now
Vision without practice is decoration. The near-term work is concrete:
- openDesk Edu â proving that a full educational workplace (LMS, conferencing, collaboration) can be sovereign and one-command deployable on Kubernetes. Back openDesk Edu with your vote đłïž â every vote counts for a sovereign, open-source education.
- MS365 exit patterns â turning "we're stuck" into "here's the 18-month path out," with exit-by-design from day one.
- Self-hosted AI â running inference locally so the assistant serves the user, not the vendor.
If you're building toward any of these phases, that's the work. The roadmap to 2055 is just the sum of thousands of organizations deciding, this quarter, that ownership is worth more than convenience.
Closing thought
A sovereign digital workplace isn't a product you buy in 2055. It's a discipline you practice starting today â decoupling one workflow, federating one partnership, owning one model. The future of work will be sovereign not because the technology forces it, but because enough of us decided it was worth building.
This is a living document. The phases will be revised as reality argues back. The principles won't.