One verified ID.Zero friction. Instant trust.
Let consultants, partners and vendors prove who they are using credentials their employer already issued. Grant precise access in seconds — and automatically revoke everything the moment that credential is no longer valid.
Built on W3C Verifiable Credentials, OIDC4VC and SD-JWT
Kira needs Brandon in by Friday. By Monday he might be gone.
This is how modern B2B collaboration actually works — and why traditional guest accounts fail.
Alpha Trading Co, a global investment firm, regularly works with ACME Advisory on high-stakes M&A deals. Security teams at both companies completed due diligence and established a formal trust relationship in QuartzPass.
Kira needs Brandon, a senior manager at ACME, in Alpha’s deal room, financial models and internal channels for the next six weeks. Brandon has never worked with Alpha before. There is no guest account — and there does not need to be one.
Brandon presents the credential ACME already issued him, containing his name, title and employment status. He is in, with the right role and deal-specific access, in under a minute. No password. No ticket. And the moment he leaves ACME, he disappears from Alpha.
The trust comes first
Two security teams agree, once, that each will accept credentials the other issues. Nothing in that agreement concerns any individual — it is what makes every later request cheap.
How it works
Four parties. One source of truth. Zero standing risk.
Establish trust
Security teams at both organizations mutually approve a trust relationship inside QuartzPass, with an optional due-diligence workflow.
Request external access
Any authorized internal user selects “New external access” and enters the partner’s corporate email. QuartzPass instantly recognizes the trust.
Present the credential
The external user receives a secure link and presents their employer-issued credential — authenticator app, wallet or corporate IDP — to cryptographically prove identity and claims.
Continuous validation
QuartzPass regularly verifies the credential is still active with the issuing organization. Revocation at source means instant, automatic decommissioning at every relying party.
Requesting access, without contacting anyone
An authorized internal user picks the access and enters the partner’s corporate address. The platform recognises a domain it already trusts. No ticket, and nobody at the partner is asked to confirm employment.
Proving it, and what travels with the proof
The external user presents the credential their employer already issued. Job title, seniority and department arrive as assertions from the organisation that employs them — not as fields somebody typed into a form.
And the day it is revoked
The credential is re-verified with the issuer on a cycle rather than remembered. When the answer changes, the guest identity and every permission derived from it go with it.
Capabilities that change how you work with the outside world
Not just another guest account. A living, verifiable relationship.
Employer-issued claims
Pull verified attributes directly from the partner’s IDP — job title, seniority, department, clearance level, employee ID — without manual data entry or spreadsheets.
Continuous verification
QuartzPass does not rely on a one-time check. It continuously confirms the credential is still valid with the issuing organization.
Automatic decommissioning
When the external user’s credential is revoked at their employer, QuartzPass instantly withdraws their identity and every permission across connected systems.
Passwordless by design
No more shared passwords, no more “forgot password” tickets from consultants. They authenticate with the same strong credential their employer trusts.
Native IGA integration
Credential-verified guests are first-class citizens in your governance, access reviews, SoD policies and lifecycle workflows — not a bolted-on afterthought.
Audit-grade evidence
Every verification, claim assertion and revocation event is immutably logged. Perfect for SOC 2, ISO 27001, financial services regulators and customer audits.
Works with what you already run
QuartzPass issues and verifies the credential. Your identity platform decides what it unlocks — whichever platform that is.
Native with QuartzID
QuartzID consumes QuartzPass credentials directly, so verified externals land inside the same governance, access reviews and lifecycle workflows as everyone else.
Open standards, not lock-in
Built on W3C Verifiable Credentials, OpenID for Verifiable Credentials and SD-JWT. Any conformant wallet or issuer interoperates — no proprietary bridge required.
Any IGA or IAM platform
Entra ID, Okta, SailPoint, Saviynt, Ping and the rest integrate through SCIM, SAML, OIDC and REST. QuartzPass sits alongside what you have rather than replacing it.
Verified credentials vs traditional guest accounts
What changes
Join our free launch phase through 2027
Essentials and Professional are free until December 31, 2027 — full access now, and 60 days’ notice before any billing starts.
Built for the way modern enterprises actually collaborate
Ready to replace risky guest accounts with real trust?
See exactly how QuartzPass works with your existing identity providers and partner ecosystem.
Typically live in production within 6–8 weeks.
Frequently Asked Questions
Latest Insights
Stay updated with our latest articles and insights
