Affiliated Hospital Federation
A network of affiliated hospitals federated identity across independent facilities, so rotating clinicians worked at any site under one identity while each hospital kept its own directory and audit boundary.
A regional network of affiliated hospitals shared physicians, residents, and specialists who rotated across facilities, but each hospital ran its own directory and was legally a separate entity. A cardiologist covering three sites had three accounts, three onboarding processes, and three places to be forgotten about when their privileges changed. Credentialing and access lived in silos that did not talk.
The network needed one identity per clinician that worked at any affiliated site, without any hospital surrendering ownership of its own users or its own audit boundary.
The challenge
Affiliation is not merger. Each hospital insisted on remaining authoritative over its own directory, its own records, and its own audit; regulators treated them as distinct covered entities. Yet a rotating clinician should not be re-created from scratch at every site, and access granted at one hospital must not silently leak into another. The network wanted federation with hard boundaries — shared identity, isolated tenancy.
They needed a control plane where one clinician identity could be recognized across facilities while each facility’s data and policy stayed sealed.
What Veripass deployed
Veripass federated the affiliated hospitals as separate tenants under one platform. Each hospital remained a first-class boundary: its members, policies, records access, and audit history stayed isolated and never crossed into another facility. A rotating clinician held one federated identity that each tenant could recognize and grant local access to, rather than a fresh account per site.
Each hospital kept its directory authoritative, federating over OIDC, with SCIM synchronizing account lifecycle from the source of truth. When a clinician was granted privileges at a facility, that grant was scoped to that tenant through claims, capabilities, roles, and access profiles; revoking it elsewhere left the others untouched. Every access was written to that tenant’s immutable audit trail.
- Multi-tenant federation isolating each affiliated hospital
- One federated clinician identity recognized across facilities
- OIDC federation to each hospital’s authoritative directory
- SCIM provisioning and deprovisioning from upstream directories
- RBAC from claims, capabilities, roles, and access profiles scoped per tenant
- Context-aware policy evaluated within each facility’s boundary
- Per-tenant immutable audit trails preserving each entity’s boundary
When a rotating clinician moved from one hospital to another, they authenticated against their home directory and received a session scoped strictly to the facility they were entering — privileges from another site never bled across, satisfying each hospital’s status as a separate covered entity.
Outcome
A clinician covering three hospitals collapsed three accounts and three onboardings into one federated identity, granted locally wherever they had privileges. Cross-site credentialing that meant re-creating an account became a scoped grant against an existing identity, and revoking privileges at one facility no longer risked the others.
Each hospital kept full ownership of its directory, its records, and its audit boundary, while the network finally had a coherent answer to which clinician held what access, at which facility — federation without anyone giving up control.
More deployments
Cross-Industry Workforce Federation
A holding company unified identity across retail, finance, and facilities operations into one federated control plane, so shared staff move between business units without duplicate accounts.
Global Bank Identity Hub
A multinational bank consolidated dozens of fragmented login surfaces into a single Veripass control plane, federating Entra ID and Google Workspace while keeping every regional directory authoritative.
University Adaptive Learning SSO
A university unified its adaptive-learning platforms behind a single Veripass sign-on, federating the campus directory over OIDC so students moved between tools without re-authenticating.


