IoT & Smart-Lock Integration
A facilities operator brought thousands of smart locks and IoT controllers under one identity-governed access fabric, so every door event was attributable to a verified person or device.
A facilities operator managed physical access across dozens of buildings using a patchwork of smart locks, gateway controllers, and access panels from several vendors. Each device family had its own credential scheme, its own log format, and no shared notion of who a person actually was. When an incident happened, reconstructing “who opened that door, and were they allowed to” meant stitching together exports from three disconnected systems.
The operator needed one identity-governed fabric where every lock, every gateway, and every human actor authenticated against the same control plane.
The challenge
The hardware estate was heterogeneous and could not be ripped out. Locks spoke to local gateways; gateways called cloud services; cloud services trusted whatever token they were handed. There was no consistent way to bind a door event to a verified identity, and machine-to-machine traffic between gateways and the backend used long-lived shared secrets that nobody rotated.
Auditors wanted attribution for every actuation, and security wanted to revoke a person or a compromised device instantly, everywhere, without walking the floor.
What Veripass deployed
Veripass became the identity and authorization layer in front of the device fleet. Each building was modeled as a tenant, isolating its members, devices, policies, and audit history. Human actors authenticated through their organization’s directory, federated over OIDC, and received sessions scoped to the buildings and doors their access profile allowed.
Gateways and controllers were treated as first-class machine identities. Each gateway authenticated with a scoped API key rather than a shared secret, so a compromised controller could be revoked individually without re-keying the entire site. Every actuation request was evaluated against context-aware policy — actor, role, building, time window — before a lock was told to open, and every decision was written to an immutable audit trail.
- Multi-tenant model isolating each building and its device estate
- OIDC federation for human actors via the organization directory
- Per-gateway API keys for machine-to-machine traffic, individually revocable
- RBAC composed from claims, capabilities, roles, and access profiles
- Context-aware, policy-based evaluation per door and time window
- Adaptive, step-up MFA over phone TOTP for high-security zones
- Immutable audit trail binding every actuation to a verified identity
For sensitive zones — server rooms, cash handling areas — policy demanded a step-up: adaptive MFA over phone TOTP before the door would release, even for an otherwise authorized holder. The session elevation was logged alongside the actuation, so the trail showed not just that a door opened, but that the actor proved themselves first.
Outcome
The operator collapsed three vendor-specific access logs into one consolidated, immutable trail where every door event named a verified person or a known device. Revoking access became atomic: disabling a person upstream or revoking a gateway’s API key took effect across the whole estate immediately, with no site visit.
Most importantly, physical access stopped being a black box. Every actuation now answered who opened the door, in which building, under what policy, and whether they had to step up to do it — without replacing a single lock.
More deployments
Franchise Tenant Isolation
A luxury brand operating through independent franchise partners gave each franchisee a fully isolated identity tenant, so partner staff and client data never cross boundaries while the brand keeps central governance.
Wealth Advisor Privileged Access
A wealth-management firm locked down advisor access to client portfolios with context-aware policy and biometric step-up, ensuring privileged actions required proof of identity, not just a valid session.
Affiliated Hospital Federation
A network of affiliated hospitals federated identity across independent facilities, so rotating clinicians worked at any site under one identity while each hospital kept its own directory and audit boundary.


