Edge Gateway Hybrid Deploy
A utility ran Veripass in a hybrid topology so on-prem edge gateways kept authenticating access during network outages while still federating to a cloud control plane for governance and audit.
A utility operated remote substations where access control could not depend on the internet. Sites lost connectivity for hours during storms, yet field crews still had to get through gated equipment yards, and the operator still had to prove afterward exactly who entered and when. A pure cloud identity service would have left those gates dead the moment the link dropped.
The utility needed local authentication that survived outages, paired with central governance that never lost the audit thread.
The challenge
The requirements pulled in two directions. Edge gateways at each substation had to authenticate and authorize access locally, with no round trip to a distant data center, because the network was the least reliable part of the system. At the same time, security wanted one place to define policy, one identity per worker, and one consolidated audit trail — none of which can live purely at the edge without drifting out of sync.
They needed a hybrid topology: enforcement at the edge, governance in the cloud, and reconciliation between them.
What Veripass deployed
Veripass was deployed in a hybrid model. A cloud control plane held the authoritative identities, policies, and consolidated audit; on-prem gateway nodes at each substation enforced access locally. Policies and entitlements — composed from claims, capabilities, roles, and access profiles — were distributed to the edge so a gateway could authorize a crew member against locally held identity material even with the uplink down.
Each gateway authenticated to the control plane as its own machine identity using a scoped API key, so a substation node could be enrolled or revoked individually. When connectivity returned, the edge replayed its locally recorded access events into the central immutable audit trail, reconciling the offline window without gaps.
- Hybrid topology: cloud control plane plus on-prem edge enforcement
- Local authentication and authorization that survives network outages
- Policy and entitlement distribution to the edge from a single source of truth
- Per-gateway machine identity with scoped, revocable API keys
- Context-aware, policy-based access evaluated locally at the substation
- Offline event capture reconciled into the central immutable audit trail
Sensitive operations — opening a high-voltage enclosure — still demanded a step-up where a second factor was available, and the edge degraded gracefully to its locally cached policy when it was not, recording the degraded-mode decision so reviewers could see exactly how each entry was authorized.
Outcome
Substation gates kept working through outages instead of failing closed or, worse, failing open. Crews authenticated locally and got in; the operator did not have to choose between availability and control. When links recovered, every offline entry flowed into the central trail, so the consolidated audit had no blind spots even for the hours a site was dark.
The utility ended up with one identity per worker and one policy source, enforced wherever the worker actually stood — cloud, on-prem, or a substation cut off from both.
More deployments
Faculty & Staff Provisioning
A university automated the full lifecycle of faculty and staff access with Veripass SCIM provisioning and role-based entitlements, so accounts appeared on day one and vanished on departure.
Medical Device On-Prem IAM
A hospital ran Veripass fully on-premises to govern access to networked medical devices inside its clinical network, keeping identity, policy, and audit within its own walls.
Seasonal Staff Lifecycle
A luxury retailer automated identity provisioning and same-day deprovisioning for thousands of seasonal hires, closing the orphaned-account gap that holiday peaks used to leave behind.


