Cardholder management

The roll, the photographs, and the record that outlives both

Cardholder management is where card projects succeed or stall. Sync your people from Microsoft Entra ID, Google Workspace, an API or your own database, collect photographs without running a photo day, and keep a single record per person across every card they are ever issued.

Where your people come from

Connect the roll, don't retype it

Your people already live in a directory, a student management system or an HR database. The platform reads from where they are, and you can mix sources, because every route lands on the same cardholder record with the same audit trail.

Microsoft Entra ID

Cardholders synchronised from your Entra ID (Azure AD) tenant: new staff and students appear ready to photograph and issue, and leavers deactivate. Single sign-on comes with it.

Google Workspace

The same for Workspace schools and institutions, your directory decides who exists, and Google sign-in gets operators and cardholders in without another password.

API and webhooks

A REST API to create, update and query cardholders, and webhooks that tell your systems when cards are issued or revoked, so your student management or HR system stays in charge.

Direct database connection

A small on-site agent queries SQL Server, PostgreSQL or MySQL directly and syncs changes both ways, built for the legacy system that has no API but still holds the truth.

Spreadsheet import

Still there, and still the fastest day one: export from anything, map the columns, preview, import. Re-imports update existing records rather than duplicating them.

Photo collection without the queue

The slowest part of issuing cards is getting a usable photograph of every person. Send an emailed photo invitation and cardholders upload from their own phone, wherever they are. Nobody staffs a camera, and nobody stands in a corridor.

Screened automatically

Each upload is checked against an ICAO 9303 / ISO portrait model, head size and position, background, sharpness, exposure, before it reaches a human.

Cropped correctly

The detected head is mapped onto a 35×45 portrait with proper headroom, so cards look consistent even though the photographs were taken on a hundred different phones.

Reviewed by people

Staff approve or reject in a purpose-built queue. The rejection reason goes back to the cardholder so they can retry without contacting anyone.

One record, many cards

A cardholder is a person, not a print job. Their record carries every card they have held, every photograph they have submitted, and every order they have appeared on, which is what makes a replacement card a two-minute job rather than a fresh start.

  • Connected sources: Entra ID, Google Workspace, an API, a direct database connection, or a spreadsheet import.
  • Scoped access by organisation, campus or faculty, controlled by role.
  • Status that means something: active, inactive or archived, separate from the state of their card.
  • Self-service so cardholders can check their own photograph and digital ID.

Built for privacy obligations

Identity photographs are personal information, and institutions in New Zealand and Australia are accountable for how long they keep them and who can see them. The platform is built to make that answerable rather than aspirational.

  • Configurable retention for approved and rejected photographs, per organisation.
  • Data requests from cardholders handled in the platform.
  • Audit log of every change, with the person who made it.
  • Tenant isolation enforced at the database as well as in the application.
Common questions

Frequently asked

How do cardholders get their photo to us?

They receive an emailed photo invitation with a secure link, valid for three days, and upload from their phone. No app to install and no account required.

What makes a photograph fail the check?

The pre-screen is modelled on ICAO 9303 portrait rules: the head must occupy roughly 70 to 80 percent of the frame height with eyes in the upper third, on a plain background, in focus and correctly exposed. Staff still make the final decision.

Can we import from our student management system?

Yes, and you may not need an export at all. Cardholders can be synchronised from Microsoft Entra ID or Google Workspace, driven through the REST API and webhooks, or read directly from a SQL Server, PostgreSQL or MySQL database by a small on-site sync agent. A spreadsheet import with column mapping is always there for day one and one-off cohorts.

How long are photographs kept?

That is your decision, set per organisation. Approved and rejected photographs have separate retention periods, and expired images are removed automatically by a scheduled process.

See it against your own process

Tell us how you issue cards today and we will show you what this looks like for your institution. No obligation, and no sales script.