In healthcare, providers aren't hired โ they're credentialed. The Medical Staff Office is a second authoritative source alongside HR, and Epic role/template assignment is its own governed step. So the ownership map has more lanes than a typical enterprise โ but it is exactly the shape the lab's HRIS โ IGA โ ITSM โ PACS + Duo fabric already governs. This page is the customer-facing reference a technical leader brings to a healthcare Duo engagement.
Joiner is credential-driven; leaver inverts to disable-first, notify-after, with a single signed SSF/CAEP event pulling logical and physical access together.
sequenceDiagram participant HR as HR / Workforce participant MSO as Medical Staff Office participant IAM as IAM / Identity participant EPIC as Epic Security participant DUO as Duo ยท MFA / SSO participant IGA as IGA / Governance participant PACS as Physical Access Note over HR,MSO: JOINER โ credential-driven MSO->>MSO: credential + privilege โ SER record HR->>IAM: staff worker record MSO->>IAM: provider identity IAM->>DUO: enroll MFA + tap-and-go IAM->>EPIC: request Epic template EPIC->>EPIC: assign role / subtemplate IAM->>PACS: badge to assigned units IGA->>IGA: baseline access cert + SoD Note over HR,PACS: LEAVER โ disable-first, notify-after MSO->>IGA: privilege end / termination IGA->>IAM: disable identity IGA->>DUO: session-revoked (SSF / CAEP) DUO-->>EPIC: kill EHR session DUO-->>PACS: revoke badge
Nine lifecycle activities across the seven owners in an Epic acute facility. Clinicians invoke break-glass and the data/application owner approves access requests โ both fold into Consulted below.
| Activity | HR | Med Staff | IAM | Epic Sec | IGA | SOC/ITDR | Compliance/HIM |
|---|---|---|---|---|---|---|---|
| Onboard staff (nurse / tech) | A | โ | R | C | I | โ | I |
| Credential + onboard provider | C | A | R | C | I | โ | C |
| Epic role / template assignment | โ | C | C | A | C | โ | C |
| Access request (add'l system) | โ | C | R | C | A | โ | I |
| Mover (unit / role / locum) | A | C | R | C | C | โ | I |
| Leaver + real-time revoke | C | C | A | R | R | C | I |
| Break-glass emergency access | โ | C | I | R | I | R | A |
| Access certification / recert | I | C | C | C | A | โ | C |
| HIPAA access audit / ITDR | โ | โ | I | C | C | R | A |
Every owner lane above is a component the lab already runs โ the rehearsal is the customer's org chart in miniature.
The point isn't a new product โ it's that this ownership map already exists in the customer's org. The fabric just makes each lane a governed, auditable step on the identity they already run: Duo as the decision point, the same joiner/mover/leaver, extended to Epic roles, break-glass, and the door. A technical leader can walk a healthcare customer from "we govern access by hand across HR, the Medical Staff Office, and Epic" to "one identity truth, continuously governed, with real-time revoke."
โ related: Ownership & category model (page 2) ยท the validation deck โ