Physical Identity & Access Management

One identity. Every system. Every door.

From the HR record to the door reader - ID-ware unifies physical and logical access across every building, system, and contractor.

ID-ware / Identity
2.4M identities 12M reads/day 99.999% uptime
Live
JO
Jordan Okafor Active
Contractor · Engineering · ID 4421 · Source: Oracle HCM
Identity lifecycle
  • HR record reconciled Oracle HCM
  • Accounts provisioned AD · Entra ID · Okta
  • Credential issued DESFire EV3 + mobile
  • Door access granted role-based, time-windowed
Live access
  • 14:32 Data Hall DH-04 Granted
  • 14:28 Turnstile L2 Granted
  • 14:21 Server Room S1 Denied
  • 14:19 Lobby mantrap Granted
< 6 spolicy to door

01 The identity journey

Follow one identity through every system.

From HR onboarding to leaver revocation, one golden record flows through every gate, every door, every log - without manual intervention.

  1. Step 01

    HR record created

    A new starter appears in Oracle HCM, SuccessFactors, or Workday. Role, department, location, start date - the source of truth for who they are and what they need.

    Oracle HCMWorkdaySuccessFactors
  2. Step 02

    Golden identity reconciled

    The identity broker dedupes and reconciles against every downstream system. One canonical record - no more "John Smith" vs "J. Smith" vs employee #4421.

    SailPointIdentity BrokerEntra ID
  3. Step 03

    Accounts provisioned

    AD, Entra, Google Workspace, and every connected SaaS app get the right accounts with the right entitlements - provisioned in minutes, not days. Birthright access before the welcome email goes out.

    Active DirectoryEntra IDOktaGoogle Workspace
  4. Step 04

    Physical credential issued

    A DESFire EV3 card is encoded and a mobile wallet credential is pushed. Whether they're remote or on-site, day one starts with a working badge - not a queue at reception.

    HID OrigoNedap AEOSApple Wallet
  5. Step 05

    Doors respond to identity

    Every reader - from the lobby turnstile to the Nedap mantrap in the data hall - authorises against the same golden record. Role-based access, time-windowed, and audited live.

    Nedap AEOSHID VertXPaxton Net2
  6. Step 06

    Audit lineage complete

    Every provisioning decision, every door swipe, every role change - cryptographically signed and attributable. Evidence ISO/IEC 27001, NIS2, and regulator audits with a single export.

    SplunkDatadogSentinelChronicle
  7. Step 07

    Leaver revoked - same day

    HR marks the leaver date. Within minutes, every account is disabled, every credential revoked, every door closed. No shadow access. No Tuesday-morning surprises.

    Oracle HCMADNedap AEOSHID Origo

03 Trust

Checked, stamped, approved.

Independently certified and sovereign by design. Every figure on this sheet is measured, not estimated.

Identity sync SLA 99.9%
Source-to-directory propagation SLA 15 min
P1 response SLA 15 min
Founded 2005
Sovereignty UK & EU sovereign cloud
AWS eu-west-2 (London)
eu-central-1 · EUSC
Certifications ISO 9001 · ISO/IEC 27001
TISAX (DEKRA-certified)
GDPR / NIS2 / DORA support

Independently certified: ISO 9001, ISO/IEC 27001 and TISAX (DEKRA-certified), with GDPR / NIS2 / DORA support. Hosted in UK & EU sovereign cloud - AWS eu-west-2 (London) · eu-central-1 · EUSC.

04 The backbone of access

One identity. Every system. Every door.

From the first HR record to the last door closed - every authorisation radiates from one golden identity.