> For the complete documentation index, see [llms.txt](https://docs.fortifiedid.se/control/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.fortifiedid.se/control/common-use-cases/common-use-cases.md).

# Common use cases (ENG)

Common use cases for Fortified ID Control.

This section is intended to help the reader relate to what Fortified ID Control can be used for in practice.

## Example scenarios

[User certifications](#user-certifications) | [API-driven process orchestration](#api-driven-process-orchestration)\
[Delegated data management](#delegated-data-management) | [Business process automation](#business-process-automation)\
[Scheduled identity and group updates](#scheduled-identity-and-group-updates) | [External user self-registration](#external-user-self-registration)\
[Delegated user management](#delegated-user-management) | [Group self-service management](#group-self-service-management)\
[Shared group ownership](#shared-group-ownership) | [Automated group management](#automated-group-management)\
[Joiner-Mover-Leaver (JML)](#joiner-mover-leaver-jml) | [Privileged identity management (PIM)](#privileged-identity-management-pim)\
[Access request and approval](#access-request-and-approval) | [Account expiration management](#account-expiration-management)

### User certifications

**Use case**\
Organizations want to regularly verify that access is still correct, but also that ownership and responsibility are correctly assigned. This can include confirming that users still have the right access to groups, roles, and resources, as well as verifying that managers or other responsible persons are still connected to the right users, teams, or objects. This helps improve governance, reduce unnecessary access, and keep responsibility structures up to date.

**How it maps to Fortified ID**\
Fortified ID `Control` can manage the certification process by using `Schedules` to trigger review cycles and `Forms` to let responsible persons review and act on the current situation. Typical actions can include approving existing access, removing users from a resource, reassigning ownership, or updating who is responsible for a user or object. `Pipes` and `Valves` can then process the outcome and apply the updates in connected systems.

### Delegated data management

**Use case**\
In many organizations, the people who know the data best are not in IT. A manager, team lead, or application owner may need to manage membership, ownership, or selected attributes for the data they are responsible for. This makes it possible to place day-to-day administration closer to the business while still keeping control and traceability.

**How it maps to Fortified ID**\
Fortified ID `Control` can support this through `Forms` that provide a controlled self-service or delegated administration experience. Managers, owners, or other responsible persons can be given access to specific actions without exposing the full administration layer. `Pipes` and `Valves` can then validate the request, apply business rules, and update the connected systems in a consistent way.

### Scheduled identity and group updates

**Use case**\
Some changes need to happen automatically and repeatedly, for example based on data from HR, a database, or another source system. This can include updates to users, groups, or ownership information. The goal is often to reduce manual work and make sure that identity-related data stays up to date over time.

**How it maps to Fortified ID**\
Fortified ID `Control` can support this through `Schedules` that run at defined intervals and `Pipes` that read, compare, transform, and update data without requiring manual interaction. This makes it possible to handle recurring identity and group updates in a predictable and traceable way.

### API-driven process orchestration

**Use case**\
In some environments, another application needs to start a process in `Control` or pass information to it as part of a larger workflow. This is common when identity-related actions need to be embedded in a broader process that starts in another system.

**How it maps to Fortified ID**\
Fortified ID `Control` can support this through `API` endpoints and `Pipes` that validate incoming requests, process the data, and trigger changes in internal or external systems. This allows other applications to use `Control` as part of a larger orchestration flow while keeping the processing logic and integrations in one place.

### Business process automation

**Use case**\
Not every process is only about provisioning. Some organizations also need structured automation around approvals, ownership, notifications, validation, or follow-up actions. These processes often involve several steps and need to be handled in a repeatable and transparent way.

**How it maps to Fortified ID**\
Fortified ID `Control` can support this by combining `Forms`, `Schedules`, `Pipes`, and `Valves` into maintainable workflows where each part of the process is handled in a consistent way. Depending on the scenario, other Fortified ID products can also be part of the full solution, while `Control` handles the workflow, automation, and integration logic.

### External user self-registration

**Use case**\
External users such as consultants, partners, and contractors are often not managed through the organization's HR system. As a result, their accounts are frequently created manually in directories and applications, either directly in administrative tools or through delegated administration portals. Manual account creation is time-consuming, difficult to scale, and increases the risk of errors and inconsistent user data. A more secure and efficient approach is to let external users register their own accounts after first verifying their identity with a trusted electronic identity. After successful verification, the user can provide additional information such as email address and mobile number. Once the registration is submitted, designated stakeholders within the organization can be notified, and approval steps can be added so that the account creation is reviewed before access is granted.

**How it maps to Fortified ID**\
Fortified ID `Control` can provide the self-service registration experience through `Forms`, where the external user enters the required information after successful authentication. Fortified ID `Access` can handle authentication with electronic identities such as `BankID`, so the user verifies their identity before submitting additional data. `Pipes` and `Valves` can then validate the submitted information, create the account, and provision it to the target systems. Notification and approval flows in `Control` can inform designated stakeholders when a registration is submitted or requires attention, and a manager, sponsor, or resource owner can review and approve the request before the account is created or access is granted.

### Group self-service management

**Use case**\
Managing groups through centralized IT administration can be time-consuming and often creates unnecessary delays for business users. Group owners are typically the individuals best positioned to determine who should have access and how a group should be maintained. Organizations therefore need a secure and controlled way to delegate group management responsibilities to designated group owners. This can include managing group membership, updating group information, and assigning additional or replacement owners. By enabling self-service group management, organizations can reduce administrative overhead, improve data quality, and keep group ownership accurate and up to date.

**How it maps to Fortified ID**\
Fortified ID `Control` can support this through `Forms` that let designated group owners manage the groups they are responsible for without requiring access to full administrative tools. `Pipes` and `Valves` can validate the requested changes, enforce business rules, and update the connected directories or target systems. If needed, the process can also include notifications, approvals, or follow-up actions to make sure that delegated group management remains controlled and traceable.

### Shared group ownership

**Use case**\
Some organizations need more than one person to be responsible for the same group. This can be useful when ownership needs to be shared across a team, when a backup owner is needed, or when the underlying platform does not offer a practical way to manage shared ownership. By supporting multiple owners for the same group, organizations can avoid bottlenecks, reduce dependency on a single individual, and make group administration more resilient.

**How it maps to Fortified ID**\
Fortified ID `Control` can support this through `Forms`, where more than one owner can be assigned responsibility for the same group. Those owners can then manage membership and related group tasks through the same delegated flows. `Pipes` and `Valves` can enforce the ownership model and apply the required changes in the connected directory, even when the target platform itself does not provide a strong native model for delegated multi-owner management.

### Automated group management

**Use case**\
Manual group management is often time-consuming and can lead to incorrect or outdated access rights. Users may remain members of groups longer than required, or miss required group memberships when their role, department, location, or employment status changes. Organizations therefore need a way to automatically manage group memberships based on trusted user data and defined business rules. By evaluating user attributes such as department, title, organization, location, or account type, users can be added to or removed from groups automatically. This helps ensure that group memberships stay accurate, access remains aligned with current user information, and administrative work is reduced.

**How it maps to Fortified ID**\
Fortified ID `Control` can support this through `Pipes` and `Valves` that evaluate user attributes and automate group membership changes in the target systems. `Schedules` can periodically run group evaluation processes to keep memberships up to date over time. Notification flows in `Control` can inform administrators or group owners when automated changes have been performed.

### Joiner-Mover-Leaver (JML)

**Use case**\
Joiner-Mover-Leaver, often called `JML`, is a common IAM framework for managing access throughout a user's time with an organization. When someone joins, the right accounts and baseline access need to be created. When they move to a new role, outdated access must be removed and replaced with the permissions required for the new position. When they leave, accounts and access must be revoked to prevent orphaned accounts and reduce security risk. Organizations use JML to improve security, reduce manual work, and support compliance.

**How it maps to Fortified ID**\
Fortified ID `Control` can support `JML` through `Schedules`, `Pipes`, and `Valves` that react to trusted source data from HR, directories, or other systems. In `Joiner` scenarios, the flow can create accounts and assign baseline access. In `Mover` scenarios, it can remove outdated permissions and apply the new ones needed for the updated role. In `Leaver` scenarios, it can disable or remove accounts and revoke access across connected systems. Notification and review flows can also be added when stakeholders need visibility or follow-up actions during the lifecycle.

### Delegated user management

**Use case**\
User administration is often handled centrally by IT, even when the responsibility for users belongs to managers, sponsors, or other business owners. This can create delays, increase support workload, and make it harder to keep user information and access rights up to date. Organizations therefore need a flexible way to delegate user management tasks to the people who are responsible for the users. The required actions may vary depending on the owner, user type, organization, or business process. Typical examples include managing group memberships, disabling accounts, unlocking accounts, reviewing user ownership, or certifying that users still belong to a specific manager or organization. This helps reduce administrative overhead, improve data quality, and ensure that user management is performed by the right people with the right level of control.

**How it maps to Fortified ID**\
Fortified ID `Control` can support this through `Forms` that present different management actions depending on the owner, user type, or business context. `Pipes` and `Valves` can validate the request, enforce business rules, and apply the changes in connected systems. The process can also include notifications, approvals, or review steps to ensure that delegated user management remains controlled, traceable, and aligned with internal responsibilities.

### Privileged identity management (PIM)

**Use case**\
Permanent administrative privileges represent a significant security risk. Users often retain elevated access long after it is needed, increasing the potential impact of compromised accounts, insider threats, and human error. Organizations therefore need a secure and controlled way to provide privileged access only when required. By letting users activate temporary privileged access for a limited period, such as four hours, organizations can improve security, support compliance requirements, and enforce the principle of least privilege while still allowing administrators to work efficiently when elevated access is needed.

**How it maps to Fortified ID**\
Fortified ID `Control` can provide a self-service experience through `Forms`, where users activate temporary privileged access to systems, applications, or administrative roles for a defined period. `Pipes` and `Valves` can automate the assignment and removal of privileged access based on the selected time limit, and `Schedules` can automatically revoke the access when the active period expires. The full process can be logged so that other authorized persons can review when a user has activated privileged access for themselves. Fortified ID `Access` can also enforce authentication requirements, including strong authentication methods, before privileged access is granted.

### Access request and approval

**Use case**\
Organizations often need to control access to applications, systems, and other resources. Granting access without proper oversight can lead to excessive permissions, compliance issues, and security risks. To ensure that access is granted appropriately, organizations need approval workflows where one or more stakeholders, such as a manager, a resource owner, or both, review and approve access requests before access is granted.

**How it maps to Fortified ID**\
Fortified ID `Control` can provide a self-service interface through `Forms`, where users request access to applications, systems, and other resources. Approval flows in `Control` can let managers, resource owners, or other designated stakeholders review and approve the request before access is granted. `Pipes` and `Valves` can then automate the provisioning of the approved access to target systems and directories, while notification flows in `Control` keep requestors and approvers informed throughout the process.

### Account expiration management

**Use case**\
Organizations often need to manage temporary or time-limited user accounts, such as consultant or external user accounts. If these accounts expire or become locked without proper notice, it can lead to access issues, support cases, and unnecessary interruptions in ongoing work. To prevent this, responsible stakeholders such as a consultant manager or account owner need to be notified before an account is locked or expires. This gives them the opportunity to review the account and extend it if continued access is still required.

**How it maps to Fortified ID**\
Fortified ID `Control` can support this through `Schedules` that periodically identify accounts approaching their expiration date and send notifications to the responsible stakeholder. `Forms` can then provide a self-service interface where the stakeholder reviews the account and extends its validity when needed.

For practical examples, see the Control use cases:

* [Forms use cases](https://docs.fortifiedid.se/use-cases/fortified-id-control/forms)
* [Schedule use cases](https://docs.fortifiedid.se/use-cases/fortified-id-control/schedule)
