School of Ministry sealGOD'S ANOINTED
MINISTRIES, INC.SCHOOL OF MINISTRY

BUILD v4.6 · RESTRICTED OPERATIONS

Operational Administration

Manage authorized access through controlled provisioning, role-change, suspension, restoration, and deactivation workflows while preserving an auditable record.

Official School of Ministry seal

ACCESS LIFECYCLE

Identity Provider First. School Role Second.

01

Verify Identity

Create or verify the person in the approved identity provider. The School application must not store passwords.

02

Approve Role

Confirm the user’s institutional responsibility and least-privilege role before assignment.

03

Assign Access

Link the authenticated identity subject to the authorized School role in user_roles.

04

Validate

Sign in as the test identity and verify both permitted and denied functions.

05

Review

Periodically certify active access against current responsibilities.

06

Deactivate

Disable School roles promptly when access is no longer required; retain the audit trail.

CONTROLLED CHANGES

Every Access Change Must Be Traceable

ChangeRequired ControlAudit Event
New role assignmentVerified identity subject + authorized institutional needrole.assigned
Role suspensionDocumented reason; effective immediately when security requiresrole.deactivated
Role restorationReauthorization before reactivationrole.reactivated
Role changeAssign required role, validate, then remove obsolete roleSeparate assignment/deactivation events
Access reviewPeriodic certification by authorized administratoraccess.reviewed

PRODUCTION SAFEGUARD

No Password Administration in the School Database

Authentication credentials remain with the approved identity provider.

The School database stores identity subjects and authorized roles, not passwords. Password reset and account-recovery functions must be delegated to the configured authentication provider.