Identity and access management

HES LoanBox does not manage user credentials, sign-in screens, or password policies on its own. All authentication and identity management is delegated to Keycloak, an external identity and access management product. This page covers how users are authenticated, how roles and permissions govern what each user can do, and the password and lockout policies enforced at the identity layer. For the end-to-end administration flow see the User and role management section.

Authentication via Keycloak

Keycloak issues and validates the tokens that grant access to HES LoanBox. Authentication uses the OAuth 2.0 and OpenID Connect protocols; the platform trusts Keycloak-issued tokens and enforces access on every request against them.

Users and roles

Access is role-based. HES LoanBox is wired to a fixed set of role names. Every endpoint, process task, and menu permission maps to one or more of them. Roles are never assigned by the platform itself; an administrator assigns them in Keycloak. A user may hold more than one role in a realm, and permissions are additive.

Permissions model

Permissions are enforced at the endpoint level, not only in the interface: hiding a menu item does not grant access to the underlying action. The role set is designed around least privilege and separation of duties. For example, the underwriter who decides an application and the verifier who checks the underlying data hold different roles. Within an area, read-only roles can view but not change records, while full-access roles can create, edit, and approve.

Login lockout and brute-force protection

Keycloak provides brute-force detection. After a configurable number of failed sign-in attempts, the account is temporarily locked, with the wait time increasing on repeated failure; a permanent lockout requiring administrator intervention can also be configured. These thresholds are set per realm.

Sessions and tokens

Session and token lifetimes — access-token and refresh-token expiry, idle and maximum session duration, and single-logout behavior — are configured in Keycloak. Shorter lifetimes reduce the window in which a stolen token is usable; longer ones reduce re-authentication friction. The institution sets the balance.

Note

Two-factor authentication is configured in Keycloak and can be enforced for all users in a realm or conditionally for users with specified realm or client roles.

Search documentation