Physical Identity & Access Management
The identitybehind every door,ready before day one.
No new starter should wait for a card. No leaver should keep one. ID-ware unifies HR, directories and access control into a single identity record - live before day one, gone the day someone leaves.
- HR record reconciled HR connector
- Accounts provisioned directory · SSO
- Credential issued DESFire EV3 + mobile
- Door access granted role-based, time-windowed
- Data Hall DH-04 Granted · 07:00-19:00
- Labs L1-L3 Granted
- Server Room S1 Denied · requires DV
- Lobby & mantrap Granted
- DESFire EV3 · card #•••• 4421 Active · iss. 14 Jan 2026
- Mobile credential · wallet Active · pushed
- Second mobile credential Ready to provision
- Data Hall DH-04 Access profiles current
- Turnstile L2 Entitlements published
- Lobby mantrap Access profiles current
- Server Room S1 Entitlements published
- A. Mensah · Acme Ltd Host: J. Okafor · in 09:14
- R. Silva · contractor Host: Facilities · in 10:02
- Pre-booked · 13:30 Awaiting check-in
- Credential issued · J. Okafor 14:02 · signed
- Access granted · DH-04 14:32 · signed
- Policy change · Eng-contractor 13:50 · signed
- Evidence pack exported Q2 audit · one click
- 14:32 Data Hall DH-04 Granted
- 14:28 Turnstile L2 Granted
- 14:21 Server Room S1 Revoked
- 14:19 Lobby mantrap Granted
Two ways to start.
Run the whole identity estate on the PIAM Suite, or fix the ID-photo problem first with Photon.
Run the whole identity estate
One reconciled record drives directories, credentials and door policy - joiners are issued a card in under 4 minutes and leavers lose access the same day.
- Near real time policy to access control
- 50+ pre-built connectors
Print-ready ID photos, self-served
People take or upload a photo. Photon checks it against ID-photo requirements, removes the background, and hands back a clean, print-ready portrait. Privacy by design: it detects faces, it never recognises them.
- self-service capture
- 7-day Lite trial
The whole platform, or just the photos.
Every authorisation traces back to one verified identity. Take the full PIAM Suite, or begin with Photon and fix self-service ID photos first.
PIAM Suite
The identity broker between HR and the door. One golden record - live the day someone joins, gone the moment they leave.
- 1HR or student record created
- 2Golden identity reconciled
- 3Accounts and access provisioned
- 4Self-service photo capturedvia Photon →
- 5Credential printed and issued
- 6Doors respond to the identity
Photon
People take or upload their own photo; Photon returns a clean, print-ready portrait for the credential it issues.
- 1Invited by PIAM self-service← PIAM
- 2Photo taken or uploaded
- 3Quality and composition checked
- 4Background removed, portrait made
- 5Portrait returned to the PIAM record→ PIAM
- 6New card produced and sent
Authoritative sources
The broker
ID-ware identity engine
Identity broker - PIAM
UK & EU sovereign cloud
Everything downstream
The identity lifecycle, played out live.
Every moment in the identity lifecycle, from day-one provisioning to same-day revocation. Open any scenario to step through it live.
Step through all eight, at your own pace.
Play, pause, and step every message in the interactive simulation - joiner to leaver, kiosk to mantrap, with a full transcript as it runs.
Checked, stamped, approved.
Independently certified and sovereign by design. Our certifications, data residency and availability targets are verified facts, not estimates.
London - AWS eu-west-2
Frankfurt - AWS eu-central-1
AWS European Sovereign Cloud (EUSC)
Cyber Essentials Plus
Aligned: GDPR · NIS2 · DORA
Independently certified: ISO 9001, ISO/IEC 27001 and Cyber Essentials Plus. We process data under UK and EU GDPR, and our AWS deployment is aligned with NIS2 and DORA. Hosted in UK & EU sovereign cloud, with three options: London (AWS eu-west-2), Frankfurt (AWS eu-central-1), or the AWS European Sovereign Cloud (EUSC).
The identity behind every door.
From the first HR record to the last door closed - every authorisation radiates from one golden identity.