Back to case studies // federation

Cross-Industry Workforce Federation

A holding company unified identity across retail, finance, and facilities operations into one federated control plane, so shared staff move between business units without duplicate accounts.

October 7, 2024 · Veripass
Cross-Industry Workforce Federation

A diversified holding group ran several operating companies on different stacks: a retail chain on Google Workspace, a financial services arm on Microsoft Entra ID, and a facilities team on a legacy local directory. The same people frequently worked across two or three of those businesses. Every move meant a new account, a new password, and another orphaned login when the assignment ended.

The group needed one identity for each person, federated across every business unit, without forcing every company onto the same directory.

The challenge

Each operating company was authoritative about its own users and refused to surrender that ownership. The retail business would not migrate off Google Workspace; the financial arm was contractually bound to Entra ID. Yet auditors wanted a single, coherent answer to “who has access to what” across the entire group, and HR wanted a shared worker to be deprovisioned everywhere the moment they left.

The result was fragmentation: duplicate accounts per person, no consolidated audit, and deprovisioning that depended on someone remembering every system a worker had ever touched.

What Veripass deployed

Veripass became the federated control plane sitting above all three businesses. Each operating company was modeled as its own tenant, keeping its members, policies, and audit history fully isolated. Applications were registered once on the platform and then granted to the specific tenants that needed them, so a shared payroll tool could serve all three companies without any of them seeing each other’s data.

External directories stayed authoritative. The retail tenant federated to Google Workspace over OIDC, the financial tenant to Microsoft Entra ID, and SCIM kept account lifecycle synchronized from each upstream directory. A worker assigned across business units authenticated against their home directory and received a session scoped by the tenant they were entering.

  • Multi-tenant organization model isolating each operating company
  • Entra ID and Google Workspace federation over OIDC
  • SCIM provisioning and deprovisioning from upstream directories
  • RBAC composed from claims, capabilities, roles, and access profiles
  • Context-aware policy evaluation scoped per tenant and application
  • Adaptive, step-up MFA over email and phone TOTP for sensitive units
  • API keys for machine-to-machine traffic between back-office systems
  • Immutable audit trail consolidated across all tenants

Authorization was expressed through layered claims, capabilities, roles, and access profiles, so the same person could hold a cashier profile in retail and a read-only auditor profile in finance without those permissions bleeding together. When a request touched financial systems, policy evaluation demanded a step-up: adaptive MFA over phone TOTP before the session was elevated.

Outcome

The group collapsed roughly three identities per shared worker down to one federated identity, while every business kept its own directory as the system of record. Cross-unit onboarding that used to take days of manual account creation dropped to a single grant against an existing identity. Deprovisioning became atomic: removing a worker upstream cascaded through SCIM across every tenant they touched.

Most importantly, auditors finally got one consolidated, immutable trail answering who accessed what, in which business, and under what policy — without any operating company giving up control of its own users.

More deployments

Affiliated Hospital Federation

Affiliated Hospital Federation

A network of affiliated hospitals federated identity across independent facilities, so rotating clinicians worked at any site under one identity while each hospital kept its own directory and audit boundary.

Global Bank Identity Hub

Global Bank Identity Hub

A multinational bank consolidated dozens of fragmented login surfaces into a single Veripass control plane, federating Entra ID and Google Workspace while keeping every regional directory authoritative.

University Adaptive Learning SSO

University Adaptive Learning SSO

A university unified its adaptive-learning platforms behind a single Veripass sign-on, federating the campus directory over OIDC so students moved between tools without re-authenticating.