Research Data Access Control
A research university enforced fine-grained, policy-based access to sensitive datasets with Veripass, so each researcher reached exactly the data their approval covered, fully audited.
Research data carries obligations that ordinary campus access does not. A genomics dataset, a clinical cohort, a restricted archive — each comes with its own approval, its own consent terms, and its own list of who may touch it and for what purpose. A research university hosting many such datasets faced a control problem that coarse, role-based access could not express: approval is per-dataset and per-project, not per-job-title.
The challenge
The university governed research data with broad roles — “faculty,” “graduate researcher” — that mapped poorly to how approvals actually worked. A researcher approved for one dataset often had technical access to others they had no authorization to view, simply because they shared a role. De-provisioning when a project ended was manual and frequently skipped, so access outlived the approval that justified it. Data-governance committees could not easily answer who currently had reach into a given dataset.
The university needed access tied to specific approvals, evaluated by policy, and provably revocable.
What Veripass deployed
Veripass expressed dataset access through fine-grained claims, capabilities, roles, and access profiles, so authorization could be scoped to a specific dataset and project rather than a broad role. A researcher approved for one cohort received a capability for exactly that cohort — nothing adjacent came along for the ride.
Context-aware, policy-based evaluation governed each access request, weighing the researcher’s approvals, the project, and the conditions of the request. Sensitive datasets demanded step-up: adaptive MFA over email or phone TOTP, and biometric verification for the most restricted holdings. Federation with the campus directory over OIDC kept authentication anchored to existing identities, while access profiles let a governance committee grant and later revoke a project’s data reach as a unit.
Every access decision landed in an immutable audit trail attributed to the researcher, the dataset, and the approving policy — the record data-governance committees had been missing. For collaborations spanning institutions, multi-tenant federation kept each organization’s boundary intact.
- Fine-grained authorization via claims, capabilities, roles, and access profiles
- Context-aware, policy-based access scoped per dataset and project
- Step-up MFA and biometric verification for restricted holdings
- Campus directory federation over OIDC; multi-tenant for collaborations
- Immutable audit trails for every data access decision
Outcome
Researchers now reach exactly the data their approvals cover and no more, because access is scoped to the approval rather than inferred from a job title. When a project ends, its access profile is revoked as a unit, so reach no longer outlives authorization.
Data-governance committees finally have a direct answer to “who can access this dataset right now,” backed by an immutable trail of every decision. The university expanded sensitive-data collaborations, including cross-institution ones, with confidence that each dataset’s access matches its approval and that the record proves it.
More deployments
Boutique Clienteling Access
A luxury retailer secured its clienteling app so associates reach client books and purchase history only within their boutique and role, with step-up verification before any high-net-worth profile opens.
Contractor QR Visitor Passes
A campus operator issued time-boxed QR visitor passes bound to a verified contractor identity, so on-site access was scoped, auto-expiring, and revocable from a single control plane.
Fintech Open-Banking APIs
A fintech secured its open-banking API surface with Veripass API keys for machine-to-machine access and scoped, capability-based authorization, so every partner integration ran on least privilege.


