> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truu.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Frontline Access

> Passwordless, identity-bound access for shared Windows workstations.

# Overview

TruU Frontline Access delivers secure, passwordless, identity-bound access for shared Windows workstations — the terminals in hospitals, manufacturing floors, retail locations, and research facilities where multiple users share the same device. Unlike traditional Windows authentication built for single users, Frontline Access is purpose-designed for dynamic, multi-user settings where speed, security, and accountability must coexist.

With Frontline Access, every login on a shared workstation is a verified individual: it replaces passwords and shared accounts with per-user, certificate-based Windows logon.

<CardGroup cols={2}>
  <Card title="Every login is a person" icon="user-check">
    Individual, identity-bound sessions replace shared accounts. Full per-user audit trail on every device.
  </Card>

  <Card title="Passwordless by design" icon="fingerprint">
    Badge, PIN, mobile, or face. No shared secrets to steal, reuse, or reset.
  </Card>

  <Card title="Ephemeral credentials" icon="clock">
    Short-lived (\~12 hr), non-exportable certificates. Session teardown purges all artifacts at logout.
  </Card>

  <Card title="Built for rapid switching" icon="arrows-rotate">
    Sequential shift and walk-up logins without reboots. Native Windows security subsystem, no retrofits.
  </Card>
</CardGroup>

## The opportunity

Hospitals, plants, retail floors, and labs run on shared Windows workstations — and most still run on shared accounts and passed-around passwords. The result: no proof of who logged in, cached credentials exposed to the next user, sessions ripe for hijacking, and constant reset tickets. Every audit, incident investigation, and cyber-insurance review lands on the same finding — individual accountability is missing where the frontline actually works.

# Security and Operational Challenges in Shared Access Environments

### Credential Reuse and Sharing

Users routinely share passwords to avoid login delays, resulting in credentials that no longer map to a single identity. If one copy leaks, every system using it is exposed.

### Persistent Authentication Artifacts

Even after logoff, many authentication remnants can remain active:

* Kerberos tickets
* Browser SSO tokens
* Saved passwords
* Application session cookies

This allows subsequent users to inherit prior access unintentionally — sometimes invisibly.

### Weak Identity Binding

Passwords validate knowledge, not identity. In a shared workstation setting, this means:

* You cannot prove who performed actions on the device
* Forensics and audit investigations become inconclusive
* Compliance controls are undermined at the foundation

### Session Hijacking Risk

Long-lived tokens and idle workstation sessions make identity takeover trivial, often without obvious indicators.

### Operational Burden

Frequent password resets, account lockouts, and shared access troubleshooting increase help desk costs and slow down shift transitions.

# How TruU Frontline Access Works

<Steps>
  <Step title="Authenticate">
    A user authenticates with a badge tap, TruPIN, the TruU mobile app, or TruFace facial biometrics with deepfake-resistant liveness.
  </Step>

  <Step title="Verify and issue a certificate">
    TruU Cloud verifies the user against the enterprise directory, validates cryptographic machine trust, and issues a short-lived, smartcard-equivalent certificate that performs native Windows logon.
  </Step>

  <Step title="Single sign-on across apps">
    The session certificate drives SSO to EHR, ERP, and browser apps via Kerberos, PRT, and mTLS — one authentication per shift.
  </Step>

  <Step title="Purge at logout">
    When the user logs off, steps away, or the session times out, the certificate expires and all credentials and artifacts are purged. Nothing is left behind for the next user.
  </Step>
</Steps>

Certificates are short-lived — roughly 12 hours — and non-exportable. Frontline Access runs on the native Windows security subsystem and deploys on existing Windows endpoints and PKI, whether Cloud Trust, CyberArk, or ADCS, with no rip-and-replace.

# Why Frontline Access

<CardGroup cols={3}>
  <Card title="For security teams" icon="shield-halved">
    * Shared accounts and passwords are eliminated, not managed — every session is bound to a verified individual
    * Phishing-resistant, certificate-based authentication rooted in cryptographic machine trust
    * Ephemeral, non-exportable credentials with full session teardown at logout
    * Policy control per workstation group: badge-only for speed, or badge + TruPIN / TruFace where risk demands it
  </Card>

  <Card title="For frontline users" icon="bolt">
    * Badge-tap login in seconds — no passwords to remember, type, share, or reset
    * Rapid user switching built for shift work and walk-up use, with no reboots between users
    * One authentication per shift, with SSO into EHR, ERP, and browser apps
    * Choice of factors: badge, TruPIN, mobile app, or TruFace facial biometrics
  </Card>

  <Card title="For IT & compliance" icon="clipboard-check">
    * Per-user audit trail on every shared device, supporting 21 CFR Part 11, HIPAA, and GxP
    * Deploys on existing Windows endpoints and PKI (Cloud Trust, CyberArk, or ADCS) — no rip-and-replace
    * Password-reset and lockout tickets disappear with the passwords themselves
    * SOC 2 Type II and ISO 27001 certified platform, cyber-insurer aligned
  </Card>
</CardGroup>

# Use Cases

<CardGroup cols={2}>
  <Card title="Clinical workstations" icon="hospital">
    Badge tap to claim a session at nursing stations, med carts, and exam-room terminals. Rapid switching between clinicians.
  </Card>

  <Card title="Plant-floor terminals" icon="industry">
    Per-operator logins on manufacturing and OT workstations across shifts, with policy per line, site, or role.
  </Card>

  <Card title="Retail store systems" icon="store">
    Associates authenticate individually on back-office and store terminals. No store-wide shared password.
  </Card>

  <Card title="Regulated labs" icon="flask">
    Identity-bound sessions and per-user audit trails supporting 21 CFR Part 11 and GxP accountability requirements.
  </Card>

  <Card title="MFA where it matters" icon="key">
    Badge-only for speed, or badge + TruPIN / TruFace MFA on sensitive workstation groups — set per policy.
  </Card>

  <Card title="SSO into apps" icon="arrow-right-to-bracket">
    The session certificate drives SSO to EHR, ERP, and browser apps via Kerberos, PRT, and mTLS. One login per shift.
  </Card>
</CardGroup>

# The Path to Full Passwordless

Frontline Access is the starting point of a phased journey to enterprise-wide passwordless.

<Steps>
  <Step title="Phase 1 — Frontline Rollout · 8–12 weeks">
    Start here: shared workstations, where the risk and friction are highest.

    * Shared workstation risk assessment
    * Policy and entitlement group design per site and role
    * Badge format, directory, and PKI integration (Cloud Trust, CyberArk, ADCS)
    * Pilot, production cutover, and training
    * Audit and event pipeline standup
  </Step>

  <Step title="Phase 2 — Passwordless Expansion · 6–12 months">
    Grow: more sites, more factors, more of the workforce.

    * Site and region expansion across the frontline footprint
    * TruFace biometric rollout with liveness detection
    * TruU IDV for pre-hire, enrollment, and help-desk verification
    * Passwordless expansion to office desktops and remote workers
  </Step>

  <Step title="Phase 3 — TruU TOTAL · 12+ months, ongoing">
    The destination: continuous identity assurance across the enterprise.

    * Continuous behavioral authentication
    * Insider threat and account takeover detection
    * Identity-context SOC integration
    * Risk scoring and tuning
    * Incident response playbooks
  </Step>
</Steps>

<Card title="Next: Enabling Frontline Access" icon="arrow-right" href="/docs/sw-admin-console-policy-setup">
  Configure entitlement groups and policies to turn on Frontline Access.
</Card>
