Faculty & Staff Provisioning
A university automated the full lifecycle of faculty and staff access with Veripass SCIM provisioning and role-based entitlements, so accounts appeared on day one and vanished on departure.
Faculty and staff identity is a lifecycle problem disguised as an access problem. A new lecturer needs the right systems on their first morning; a department transfer needs old access removed as new access arrives; a departing employee must lose everything, everywhere, the moment they leave. When this is done by hand across many systems, the failure mode is predictable: people start with too little, then end with too much.
The challenge
The university provisioned faculty and staff manually, ticket by ticket, system by system. New hires waited days for access while requests worked through a queue, then accumulated entitlements over their tenure that nobody ever revisited. Departures were worse: de-provisioning depended on someone remembering every system an employee had touched, and the gaps became dormant accounts that auditors flagged year after year. A single role change could mean a dozen separate tickets.
The university needed access that followed the employment record automatically.
What Veripass deployed
Veripass tied faculty and staff access to the authoritative HR and directory record through SCIM provisioning. When a person is hired, transferred, or separated upstream, the change propagates automatically into every connected system — accounts created on day one, adjusted on a role change, and fully removed on departure, without a ticket per system.
Entitlements were expressed through claims, capabilities, roles, and access profiles, so the university modeled “tenured faculty,” “adjunct,” “department administrator,” and “IT staff” as composable roles. A new hire inherits exactly the access their role defines, and a role change swaps one profile for another rather than triggering a manual reconfiguration. Federation over OIDC with the campus directory kept authentication anchored to the identity employees already used, and context-aware policy applied adaptive step-up MFA over email or phone TOTP for administrative surfaces.
Every provisioning and de-provisioning event landed in an immutable audit trail, so the university could prove that a departed employee’s access was actually removed.
- SCIM provisioning tied to the authoritative HR/directory record
- Role-based entitlements via claims, capabilities, roles, and access profiles
- Automatic create, adjust, and remove across connected systems
- Campus directory federation over OIDC
- Immutable audit trails for every lifecycle event
Outcome
New faculty and staff now have the right access on their first day, because provisioning fires from the employment record rather than a help-desk queue. The slow-start problem disappeared, and so did its opposite: role changes swap entitlements cleanly, so people stop accumulating access they no longer need.
Departures became reliable. When an employee separates, their access is removed automatically across every connected system, and the immutable audit trail proves it. The dormant-account findings that recurred every audit cycle largely went away, because the lifecycle now closes itself.
More deployments
Edge Gateway Hybrid Deploy
A utility ran Veripass in a hybrid topology so on-prem edge gateways kept authenticating access during network outages while still federating to a cloud control plane for governance and audit.
Medical Device On-Prem IAM
A hospital ran Veripass fully on-premises to govern access to networked medical devices inside its clinical network, keeping identity, policy, and audit within its own walls.
Seasonal Staff Lifecycle
A luxury retailer automated identity provisioning and same-day deprovisioning for thousands of seasonal hires, closing the orphaned-account gap that holiday peaks used to leave behind.


