Skip to content
Boston Identity

Workforce identity

Workforce IAM

Single sign-on, MFA and the joiner, mover and leaver lifecycle for employees and contractors, built on the IAM platform you run or are moving to.

How it works

Workforce sign-in through one identity provider

Workforce sign-in through one identity providerAn employee opens an application, which sends them to the identity provider. They authenticate with a password and multi-factor authentication. The identity provider reads their groups from the directory and returns a signed token or assertion that carries them.EmployeeApplicationIdentityproviderDirectorytrust boundary1. Open appno session yet2. Sign-in requestSAML or OIDC3. Password + MFAphishing-resistant MFA4. Group lookuproles and groups5. Signed tokencarries the groups
One authentication policy, enforced at the identity provider for every application, instead of one per application.

The problem

  • Every application keeps its own login, and offboarding misses some of them.
  • MFA is enforced in some places and not others, and nobody can say exactly where.
  • Access changes for joiners, movers and leavers arrive days late, by ticket.

What we do

Workforce identity is the access your own people use every day: employees, contractors and the service accounts behind them. It sits underneath every system the business runs, so it can rarely be switched off and rebuilt. The work happens while it stays in service.

We design the authentication and federation layer, connect applications to it in waves, and automate how the platform itself is configured and released, so that a change to identity goes through the same pipeline as any other change.

What you get

  • An authentication and federation architecture that covers every application, not only the new ones.
  • Applications moved onto single sign-on in planned waves, each with a rollback.
  • MFA policy set by population and risk, and enforced at the platform rather than in each application.
  • Runbooks and release automation your own team operates.

How it is usually shaped

Usually the multi-quarter platform program that other identity work builds on.

Platforms

  • Ping Identity
  • ForgeRock
  • Okta

Engagements

  • A US consumer credit reporting agency

    Building next-gen workforce authentication platform through modern IAM product and DevOps orchestration systems.

Talk to us

Tell us where your Workforce IAM work stands, and we will reply within one business day.

Talk to us about Workforce IAM