05Industries · Manufacturing
Plants run on shared terminals and rotating crews. The terminal itself holds nothing; SenseCrypt puts a name on every session, and revocation lands the moment the contract does.
01The ceremony
SCIM brings site, assignment, and role
Verify live on their own phone or an approved kiosk
OIDC or SAML, with a scoped role
Person-level events; access ends with the assignment
02The outcomes
The next crew reaches the same terminals as fast as the last one left them. Sign-in holds up even when the whole line changes over at once.
Enrollment starts from the roster photo. When the assignment ends, deactivation flows through SCIM and access goes with it.
Roles and scopes keep production, quality, and admin systems on separate permissions.
Where personal phones don't belong, approved kiosks and industrial portals embed the verification flow natively, and the ceremony runs inside your screens.
MES, QMS, or the maintenance portal: anything that runs OIDC or SAML gets face login, with nothing ripped out or replaced.
Suppliers sign in to a tenant of their own, under your rules, with every action logged.
03The failure modes
Shared stations on the line mean shared passwords, often taped within arm's reach of the screen.
Integrators and contractors come and go weekly; access reviews run quarterly. The gap is standing risk.
Designs, recipes, and process data sit behind the same credentials people reuse everywhere else.
Plant systems and office systems each grew their own logins, and every worker carries both sets.
Critical-infrastructure audits want evidence of who accessed what. Shared logins have no answer.
Login friction at shift start multiplies by every station and every worker. The plant feels it in minutes lost.
04The compliance map
Workforce biometrics are heavily regulated, and SenseCrypt never stores any. What leaves the device is a signature, not a face; the platform holds only tokens that tell you nothing about the face they came from.
Named sign-in on shared terminals, least-privilege roles, and per-person audit events support the identification, authentication, and access-control practices in the federal guide to operational technology security.
Read the sourceNIST SP 800-63B does not treat manually entered one-time codes as phishing-resistant. Operators verify with a live face on an enrolled device instead, so there is no code to lend, pass around the line, or tape to the terminal.
Read the sourceFace matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)
Prove it on your own terminals first. The trial includes every feature for 30 days.