Access for a population that changes by design, across students, faculty, researchers and staff.
An applicant becomes a student. A student becomes a teaching assistant while still being a student. A graduate becomes an alumnus and sometimes comes back to teach. In most businesses a person joins, holds a role and leaves. Here the relationship changes repeatedly and the identity persists through all of it, which is the fact that decides how access has to work.

A postgraduate who tutors undergraduates is a student and a member of staff simultaneously, with entitlements from both. Someone moving from applicant to enrolled to graduated keeps the same identity and gets a different set of entitlements at each stage. Akku provisions from role and re-provisions on a change, so entitlements follow the current relationship rather than accumulating across every relationship the person has had. One identity, several roles, and the ability to hold two of them at once without either being manual.

Thousands of accounts have to exist and work before term starts, across the student information system, the learning management system, email and the library. Provisioning from role does that as a defined set rather than an assembled one, and bulk import handles the volume. Self-service password reset matters more here than almost anywhere: a first-week student who cannot sign in is a support queue, and there are thousands of them at once.

Research data, ethics approvals, human subject records, unpublished work and grant documentation sit with individual academics, often on their own laptops, often shared with collaborators at other institutions. Akku indexes your own records as fingerprints and detects them wherever they move: an email attachment, a browser upload, a USB stick, a cloud folder shared outside the institution. Removable media is allowed or denied by device, or left available with the file content deciding what may go onto it.

Visiting academics, external examiners, research partners at other universities and industry collaborators all need into systems you run. Federation lets them authenticate against their own institution rather than an account you create and forget, and where an account is unavoidable it comes from a role with a defined window and an expiry.

Shared workstations are used by whoever sits down at them, all day. The access decision has to happen at sign-in rather than at setup, which is what single sign-on with a passwordless factor is for. Around that, the machines themselves stay under policy: hardening baselines applied by group, software allowlisting so the applications that run are the ones you approved, and patching in staged rings without anyone visiting a lab.

Finance, HR, estates, admissions and alumni relations run the applications every organisation runs, and they hold the payroll, the fee records and the donor data. Same treatment: entitlements from role, MFA that escalates on an unusual request, and provisioning that reaches the finance system rather than stopping at the directory.

Where the students are children, the DPDP Act raises the bar: consent has to be verifiable parental consent, purposes have to be marked as not permitted for children, and no advertising identifier may be issued to a child's account. Akku's consent machinery does each of those specifically, which matters for a school in a way it does not for a university.

Every access decision is recorded as it happens, with the user, the application, the time, the location and the factor used, in logs that are tamper-evident. Privileged access to the student information system or the finance database runs through a proxy that records the session and logs every query.
