Use cases
Real-world applications
How governments and enterprises use proConsul to orchestrate digital identity, credentials and trust services at scale — from national digital-identity programmes to enterprise credential management.
Government & public sector
National digital identity programme orchestration
Scenario
A national government is implementing a comprehensive digital identity programme encompassing national ID cards, passports, driving licences, and an EUDI Wallet. The programme must support millions of citizens, integrate with legacy population-registry systems, coordinate multiple government agencies, and align with eIDAS 2.0 requirements. The system needs to issue secure credentials, manage lifecycle operations, enable cross-border recognition, and maintain comprehensive audit trails for accountability.
proConsul orchestration
Policy engine. proConsul defines and enforces policies governing credential issuance, validity periods, renewal procedures and revocation conditions. Policies accommodate different credential types (national ID, passport, driving licence) with appropriate authority delegation to issuing agencies while maintaining central oversight.
Workflow coordination. Multi-step approval workflows coordinate between population-registry verification, biometric capture, document examination, quality assurance, and final credential production. Escalation procedures handle exceptions and disputed cases, and approvals are digitally signed for non-repudiation.
Integration hub. proConsul integrates the population registry, document-management systems, biometric-matching services, TrustVault PKI infrastructure and the idGuard wallet platform. Standard protocols (OpenID Connect, SAML) federate identity across government agencies.
Governance framework. Comprehensive audit trails document every credential operation for accountability. GDPR data-subject rights are supported through automated request processing, and eIDAS 2.0 trust-service-provider operations are engineered to align through evidence collection and reporting.
Role of idGuard and TrustVault
idGuard. Citizens receive their national identity credentials in the idGuard mobile wallet. The wallet provides secure credential storage, privacy-preserving presentation, and AI-driven monitoring for identity threats. Citizens control disclosure of attributes to relying parties, with proConsul enforcing government policies on minimum disclosure requirements.
TrustVault. All cryptographic operations are performed by TrustVault with HSM-backed key material. TrustVault generates signing keys for credential issuance, maintains the PKI hierarchy from root CA through intermediate CAs to issuing CAs, performs digital signatures on credentials, and manages certificate lifecycle including revocation-list publication.
User Consent Token (UCT) flow — a use-once, time-bound token issued by a MasterCode or TrustCode to a Relying Party ID (RPID), then presented to fetch data from the wallet
International & cross-border
Cross-border EUDI Wallet pilot
Scenario
Multiple EU member states are conducting a pilot for cross-border EUDI Wallet interoperability. Citizens from one member state need to use their nationally issued digital credentials for government services, banking and healthcare in other member states. The pilot must demonstrate technical interoperability, establish trust between national infrastructures, implement mutual-recognition agreements, and respect data-protection requirements across jurisdictions.
proConsul orchestration
Trust framework management. proConsul maintains the cross-border trust framework defining mutual-recognition rules, attribute mapping between national schemas, assurance-level equivalencies and liability arrangements. Each member state operates its own proConsul instance with federation configuration enabling cross-border transactions.
OpenID Federation. proConsul implements OpenID Federation to establish trust chains between member-state identity providers, wallet providers and relying parties. Entity statements, trust anchors and metadata are managed through proConsul's federation module, with trust-chain validation occurring in real time during cross-border transactions.
Attribute mapping & translation. When credentials issued by one member state are presented in another, proConsul orchestrates attribute mapping based on agreed schemas. Privacy-preserving selective disclosure ensures only necessary attributes are shared, and consent-management workflows record citizen authorisation for cross-border data sharing.
Governance coordination. Each member state maintains GDPR alignment within its jurisdiction while proConsul coordinates cross-border data-protection safeguards. Audit logs in each jurisdiction document incoming and outgoing credential transactions, and data-localisation policies are enforced where required.
Role of idGuard and TrustVault
idGuard. Citizens use idGuard wallets to store credentials from their home member state and present them to relying parties in visited member states. The wallet handles protocol translation and credential-format conversion where necessary, with multi-language support for citizens and relying parties across the EU.
TrustVault. Each member state's TrustVault maintains its national PKI hierarchy. Cross-border trust is established through CA cross-certification or bridge-CA arrangements orchestrated by proConsul. TrustVault validates credentials issued by foreign member states against their PKI infrastructure, with validation results cached for performance.
Financial services
Banking KYC & customer re-identification
Scenario
A major retail bank must align with stringent KYC/AML regulations requiring customer identity verification at onboarding and periodic re-identification. Traditional processes involve in-branch document checks or postal identity verification, creating friction and operational costs. The bank wants to leverage government-issued digital credentials for seamless KYC while maintaining regulatory alignment, fraud prevention and audit-trail requirements.
proConsul orchestration
Identity-proofing workflow. When a customer initiates account opening, the bank's application requests identity verification through proConsul. proConsul orchestrates the workflow: the customer authenticates with their national eID, authorises disclosure of required attributes (name, date of birth, address, national ID number), and consents to the bank's processing. The verification response includes cryptographic proof of credential validity and issuing authority.
Risk-based authentication. proConsul integrates fraud signals and risk scoring. High-risk indicators (geographic anomalies, device fingerprinting, behavioural analytics) trigger enhanced verification workflows requiring additional evidence or manual review. Risk assessments are documented for AML alignment, and automated decisioning for low-risk cases accelerates onboarding.
Credential validation. Real-time validation against the credential issuer's systems confirms the credential has not been revoked. Digital-signature validation ensures credential integrity, attribute values are extracted and provided to the bank's core banking system, and validation results include an assurance-level assessment per the eIDAS framework.
Governance documentation. A complete audit trail documents the identity-verification transaction for regulatory examination — customer-consent record, credential details (without storing the credential itself, per GDPR minimisation), validation results, risk assessment and decision rationale — retained per AML record-keeping requirements.
Role of idGuard and TrustVault
idGuard. The customer's government-issued identity credentials are stored in their idGuard wallet. When the bank requests verification, the customer receives a notification in idGuard showing which attributes are requested and for what purpose. The customer reviews and approves the disclosure, and idGuard presents the credential to the bank's verification service with cryptographic proof.
TrustVault. The bank operates a qualified electronic-signature service through TrustVault integration. When the customer signs account-opening documents, TrustVault generates qualified signatures engineered to align with eIDAS requirements. For high-value transactions, TrustVault provides remote qualified signature-creation device (QSCD) capabilities, and all signing operations are logged and timestamped.
Telecommunications
Telecom SIM registration & fraud reduction
Scenario
A telecommunications operator must align with mandatory SIM-registration regulations requiring verified customer identity for all mobile subscriptions. Objectives include reducing SIM-swap fraud, preventing anonymous phone-based scams, supporting lawful-intercept requirements and improving customer experience. The operator manages millions of subscribers across retail stores, online channels and authorised dealer networks, all requiring consistent identity-verification processes.
proConsul orchestration
Multi-channel identity verification. proConsul orchestrates verification across channels. In retail stores, staff use tablets to scan the customer's idGuard wallet QR code or NFC presentation. Online, customers authenticate with a national eID and authorise disclosure. Dealer networks submit verification requests through proConsul APIs with cryptographic evidence of credential validity.
SIM-swap protection. When a subscriber requests a SIM replacement, proConsul enforces enhanced verification workflows. The customer must re-authenticate with strong credentials and authorise the SIM change; an out-of-band notification is sent to the existing phone number; and risk scoring considers request timing, location and behavioural patterns. High-risk requests require additional verification or cooling-off periods.
Fraud-detection integration. proConsul integrates with the operator's fraud-management system and external fraud-intelligence networks. Patterns indicating SIM-box fraud, subscription fraud or account takeover trigger automated protective actions; suspicious SIMs are flagged for monitoring; and bulk analysis identifies fraud rings operating across multiple accounts.
Regulatory alignment. proConsul maintains comprehensive subscriber-identity records including verified attributes, verification method, timestamp and evidence retention. Lawful-intercept requests are processed through proConsul with appropriate authorisation and audit logging, and data-retention policies automatically expire records per telecommunications regulations.
Role of idGuard and TrustVault
idGuard. Subscribers use idGuard wallets for seamless SIM activation and management. When purchasing a SIM, the customer presents a credential via QR code or NFC; for SIM swaps, enhanced authentication through idGuard prevents unauthorised changes; and idGuard's AI-driven fraud detection alerts customers to suspicious activity on their mobile accounts.
TrustVault. The operator issues digital certificates to subscribers for advanced services such as enterprise VPNs, secure messaging and IoT device authentication. TrustVault manages the operator's PKI infrastructure, generates per-subscriber certificates, and handles certificate lifecycle. Mobile-network authentication integrates TrustVault certificate validation for high-security applications.
Healthcare & professional services
Healthcare professional credentialing
Scenario
A healthcare system employs thousands of physicians, nurses, pharmacists and allied-health professionals across multiple hospitals and clinics. Professional credentials must be verified, privileges granted and tracked, continuing-education requirements monitored, and access to patient records controlled based on professional scope. Manual credentialing processes are time-consuming and error-prone, delaying practitioner onboarding and creating compliance risks.
proConsul orchestration
Credential verification. When healthcare professionals join the organisation, proConsul orchestrates verification of their professional credentials. Queries to medical licensing boards, professional colleges and educational institutions confirm qualifications; digital credentials from issuing authorities are cryptographically validated; and primary-source verification is documented for accreditation requirements.
Privileging workflows. proConsul manages privileging workflows where clinical leaders grant specific practice privileges (surgical procedures, prescription authorities, specialty consultations). Multi-level approval chains ensure appropriate oversight; privilege expirations trigger automatic renewal workflows; and changes in professional status (licence suspensions, malpractice events) automatically suspend privileges pending review.
Access-control integration. proConsul integrates with electronic health-record systems to enforce role-based access controls based on verified credentials and granted privileges. Physicians access patient records within their scope of practice; audit logs track all record access for accountability and quality assurance; and emergency-access procedures with enhanced logging accommodate urgent-care scenarios.
Continuing-education tracking. Continuing medical education (CME) credits and certification renewals are tracked through proConsul. Integration with CME providers automatically updates credential status; expiring certifications trigger notifications and renewal workflows; and lapsed credentials result in automatic privilege suspension until remediated.
Role of idGuard and TrustVault
idGuard. Healthcare professionals store their professional credentials, licences and certifications in idGuard wallets. When joining a new organisation or obtaining temporary privileges at another facility, they present verified credentials from their wallet, streamlining credentialing across healthcare systems and reducing the verification burden.
TrustVault. Electronic prescriptions are digitally signed using TrustVault-managed certificates. Healthcare professionals receive qualified electronic-signature certificates for signing medical records, consent forms and controlled-substance prescriptions, and TrustVault maintains the organisation's internal PKI for secure communications and system authentication.
Education
Academic credential issuance & verification
Scenario
A university issues thousands of degrees, diplomas and certificates annually. Graduates need verifiable proof of their qualifications for employment and further education, and employers and other institutions require efficient verification to combat credential fraud. The university wants to issue tamper-proof digital credentials that graduates can easily share while maintaining verification efficiency and reducing administrative burden on the registrar's office.
proConsul orchestration
Credential-issuance workflow. Upon graduation, proConsul orchestrates the issuance process. Student records are verified, degree requirements confirmed, and approval workflows route through department chairs, the registrar and academic senate. A digital diploma is generated with cryptographic signatures from university authorities and delivered to the graduate's idGuard wallet with a notification of availability.
Credential-schema management. proConsul maintains standardised credential schemas for various qualification types (bachelor's, master's, certificates, professional credentials). Schemas define required attributes (graduate name, degree type, major, graduation date, honours) and optional attributes (courses completed, grades, thesis title), and schema evolution is version-controlled with backward compatibility.
Verification service. Employers and institutions verify credentials through proConsul's verification API. The verifier receives cryptographic proof of credential validity, issuing authority and graduate identity; selective disclosure lets graduates share only necessary attributes (confirm a degree without revealing GPA); and verification transactions are logged for security monitoring and usage analytics.
Revocation management. In cases of degree revocation due to academic misconduct or credential fraud, proConsul manages the process with appropriate due-process workflows. Revoked credentials are added to revocation lists; verifiers checking status receive revocation notification; and the graduate receives formal notification through registered channels.
Role of idGuard and TrustVault
idGuard. Graduates receive their academic credentials in idGuard wallets. When applying for jobs or further education, they present credentials directly from their wallet; selective-disclosure controls enable sharing relevant qualifications without revealing transcript details; and lifetime access keeps credentials available years after graduation.
TrustVault. The university's credential-signing keys are managed by TrustVault with HSM protection. Academic credentials are digitally signed using the university's qualified certificate, providing strong cryptographic assurance, and TrustVault maintains the university's PKI infrastructure including timestamp services for proving credential-issuance dates.
Bring your use case to life
Every organisation has unique requirements. Let's discuss how proConsul can be configured for your specific use case.