Credentials you can withdraw the moment you need to
Agencies and large employers issue credentials to people whose relationship with the organisation changes — contractors who finish, secondees who move on, visitors who should have had a pass for one day. What matters is not printing the card; it is being able to prove who holds one, and stop them holding it.
Accountability by default
Every mutation is written to an audit log with the person who made it, what changed, and when. Issuing, revoking, reassigning and reprinting are all answerable after the fact, which is what an internal audit or a privacy enquiry actually asks for.
- Full audit trail on cardholders, cards, credentials and printers.
- Role-based access, scoped by agency, business unit or site.
- Single sign-on through SAML or OpenID Connect, so access ends with the staff account.
- Two-factor authentication for accounts that can issue or revoke.
Contractors, visitors and short tenures
Not every credential is meant to last three years. Expiry is set per cardholder, digital credentials can be withdrawn remotely within seconds, and a printed card that is not returned can be revoked so it stops verifying regardless of who is holding it.
- Per-holder expiry for fixed-term and contractor credentials.
- Immediate revocation, with the reason recorded.
- Digital-only issuance where no plastic is warranted.
- Public verification so a credential can be checked at a door without an app.
Questions procurement will ask
Identity photographs and cardholder records are personal information, and agencies are accountable for them under the New Zealand Privacy Act 2020 and the Australian Privacy Principles. Tenant data is isolated at the database as well as in the application, retention periods are configurable, cardholder data requests are handled in the platform, and access is controlled by role with everything logged.
We are happy to work through your security and privacy assessment directly rather than pointing at a brochure. Bring the questionnaire to the consultation.
Frequently asked
Where is our data held?
That is part of the conversation, and it depends on your requirements. Talk to us about data residency and hosting arrangements during the consultation and we will be specific rather than general.
Can we run it against our own identity provider?
Yes. Single sign-on is supported through SAML and OpenID Connect, so staff authenticate with your existing directory and lose access when their account is disabled.
How quickly can a credential be withdrawn?
A digital credential is struck through on the holder's device within seconds of revocation. A printed card stops verifying immediately, though the physical card obviously remains in their possession until it is returned.
Do you support visitor and contractor passes?
Yes, with per-cardholder expiry and separate templates by holder type, so a contractor pass is visually distinct from a permanent staff credential.
Can we complete a security assessment before committing?
Yes, and we would encourage it. Bring your security and privacy questionnaire to the consultation.
See it against your own process
Tell us how you issue cards today and we will show you what this looks like for your institution. No obligation, and no sales script.