Verify Identity
Create or verify the person in the approved identity provider. The School application must not store passwords.
GOD'S ANOINTEDBUILD v4.6 · RESTRICTED OPERATIONS
Manage authorized access through controlled provisioning, role-change, suspension, restoration, and deactivation workflows while preserving an auditable record.

ACCESS LIFECYCLE
Create or verify the person in the approved identity provider. The School application must not store passwords.
Confirm the user’s institutional responsibility and least-privilege role before assignment.
Link the authenticated identity subject to the authorized School role in user_roles.
Sign in as the test identity and verify both permitted and denied functions.
Periodically certify active access against current responsibilities.
Disable School roles promptly when access is no longer required; retain the audit trail.
CONTROLLED CHANGES
| Change | Required Control | Audit Event |
|---|---|---|
| New role assignment | Verified identity subject + authorized institutional need | role.assigned |
| Role suspension | Documented reason; effective immediately when security requires | role.deactivated |
| Role restoration | Reauthorization before reactivation | role.reactivated |
| Role change | Assign required role, validate, then remove obsolete role | Separate assignment/deactivation events |
| Access review | Periodic certification by authorized administrator | access.reviewed |
PRODUCTION SAFEGUARD