Identity management system (IDaaS)

A secure, scalable identity-as-a-service platform with multi-factor authentication and role-based access control.

Model

Identity as a service, multi-client

Security

MFA · role-based access control

Stack

C# ASP.NET · Entity Framework · React

Hosting

AWS S3 · Elastic Beanstalk · MySQL

Identity as a service for multiple clients

01 · Context

The situation

Several client applications needed the same secure sign-in and permissions, without each building its own.

02 · Challenge

What had to be true

Provide authentication, authorisation and fine-grained permissions as a shared service that scales across clients.

03 · What we built

The system

  • Authentication and authorisation with multi-factor authentication
  • Role-based access control, with per-user exceptions for special cases
  • A React and TypeScript interface for organisation and department profiles, roles and access settings
  • A C# ASP.NET Entity Framework back end with API controllers serving multiple clients
  • Front end on AWS S3, back end on AWS Elastic Beanstalk, MySQL for credentials, permissions and access logs
04 Architecture

How it works, step by step.

Step through the system, or let it play.

  1. User signs in
  2. Multi-factor check
  3. Roles and permissions resolved
  4. Token issued to the client app
  5. Access logged
SIGN INUserVERIFYMFAAUTHORISERBACroles + exceptionsSERVEClient appsAPI controllersAUDITAccess logsMySQL
05 · Outcome

A modular, secure identity layer that multiple clients use for sign-in and permissions.

06 · Stack
C#ASP.NETEntity FrameworkReactTypeScriptMySQLAWS S3AWS Elastic Beanstalk
Next case · E-commerce · WebShopify store for organic spices and oils
● Next step

Building something similar? Let's talk.

Book a 30-minute call →