Identity, Access & Email Authentication

Updated over a week ago

10 min read

Identity, Access & Email Authentication — PTCC Tech
Security Reference

Access We Control,
Email You Can Trust

Two background jobs: controlling who can reach sensitive church information, and proving that email using the Preston Trail name is really ours.

Who can reach our information.

Four tools, one goal: the right people see only what their role needs — and lose access when they should.

🔐

One secure staff login

Microsoft Entra · SSO

Staff sign in once and reach every connected app — no separate password per tool.

Why it matters

Fewer passwords, fewer ways in. Lock one account, and every app behind it is protected.

🔄

Access that starts and ends on time

SCIM · Auto account setup

When someone is hired, changes roles, or leaves, access updates everywhere automatically.

Why it matters

Nothing stays on after someone leaves. Access appears on day one, gone on the last.

🎫

Only what your role needs

RBAC · Role-based access

Access follows your role — Kids Check-In, Finance, Pastoral Care — not one person at a time.

Why it matters

A check-in volunteer never sees giving records; finance never sees counseling notes.

🔑

A locked vault for every other key

Keeper · Password manager

For tools outside the Microsoft login, Keeper is an encrypted vault — and lets staff share passwords safely. No sticky notes, no texting them around.

Why it matters

Every account gets a strong, unique password, and shared logins can be shut off in seconds. It covers the doors the main login can't.

How they fit together Entra is the front door· SCIM decides whether you hold a key at all· Roles decide which rooms your key opens· Keeper guards every key that isn't on the main ring
The Big Picture

How it all fits together.

None of this shows on a Sunday morning — that's the point. Two jobs, running quietly in the background.

Access

Information stays with the right people, only as long as their role needs it.