Universe: what one login actually changes
One login sounds like a convenience. From the operator's chair it changes onboarding, offboarding, and the answer to 'who can reach what?' — because identity is a property of the stack, not a product bolted on top.
One login sounds like a small convenience. Sit in the operator’s chair for a week and it turns out to be something else entirely: the difference between managing people and managing accounts.
Day one for a new hire
Consider what onboarding looks like on a typical stack. A new person starts Monday. Someone files a ticket per tool — one for the sales system, one for inventory, one for finance, one for the door controller. Each account gets created by whoever administers that tool, on their own schedule, with whatever permissions seemed reasonable at the time. For the first two weeks, the new hire’s main job is asking “can someone give me access to…” Access accumulates informally, and nobody ends up holding the full picture.
In StoneOS, onboarding is one action. The person is created once — identity is run by Veripass — and you grant roles explicitly: what they can enter, what they can do there. When they open Universe, they see exactly the platforms they are entitled to, and nothing else. First login, everything is there. There is no ticket queue, because there are no accounts to create — there is one identity and a set of grants.
The day someone leaves
Offboarding is where account sprawl stops being an annoyance and becomes a risk. The typical exit involves a checklist of every tool the person ever touched — and the one tool nobody remembered. Orphaned accounts are the standard way former employees keep access they should not have. Most companies do not know how many of these they carry.
In StoneOS there is one thing to revoke: the identity’s grants. Revocation propagates immediately — every platform, every app installed from the App Store, at once. There is no checklist to forget, because there is no list. Access lives in one place, so removing it happens in one place.
Answering “who can reach what?”
Every business eventually faces this question — from an auditor, a customer, an insurer, or its own management after an incident. On a fragmented stack, answering it is an archaeology project: export the user list from each tool, reconcile names that don’t quite match, guess at permissions whose meaning changed two admins ago.
In StoneOS the question has a lookup, not a project. Grants are explicit and readable in one place. If a person can do something, there is a grant that says so. If they no longer can, there is a record of when that changed and who changed it. The answer is not a best effort. It is the actual state of the system.
When SSO is a property of the stack
The industry’s answer to login sprawl is to buy single sign-on — SSO — as yet another product, bolted on top of tools that were never designed to share identity. It helps, but it papers over the real problem: underneath the shared login screen, each tool still keeps its own account records, its own permission model, its own idea of who you are. The seams show exactly when you need them not to — during offboarding, during audits, during incidents.
Universe is not that. In StoneOS, one login is not an add-on; it is a property of the stack. Every platform was built consuming the same identity from Veripass from day one. There is no shadow account behind the scenes to drift out of sync, because there is nothing behind the scenes — the identity you see is the identity the platforms use.
That is why the small conveniences hold up under pressure. Switching platforms in one click works because it is the same person on both sides. Immediate revocation works because there is exactly one thing to revoke.
What this is worth
None of this shows up as a feature demo. It shows up as a Monday onboarding that takes minutes, an exit that leaves nothing behind, and an audit question answered before the meeting ends. One login is not the product. Operational certainty about who can reach what — that is the product.
See how Universe fits your platform mix, or talk to sales about running your access from one place.