Manifest - Access Scoping for Applications & Services

This document outlines the recommendations for access scoping at UW-Madison, particularly using Manifest to ensure that applications are only available to approved and eligible populations.

Why Access Scoping for Applications is Important

Access scoping allows you to define which users can access your application and which users cannot. Putting your service or application behind Netid Login is a great first step, but that is just the first step in the process. Generally, IAM does not recommend scoping access to all users with a NetID. Many people with a broad range of affiliations to the UW have access to a NetID. Almost always, this is often a far wider population than should actually have access to your application. Thankfully, Manifest groups serve as a good way to scope access to just the users that should be able to use your application. Whether it's large, enterprise-wide populations or smaller populations at the departmental or course-level, Manifest likely has what you need to automate data-driven access. There are many reasons why scoping access is important, and a couple of the more prominent reasons are discussed below.

Regarding compliance, many of our externally vended applications have stipulated contract guidelines regarding who should have access to an application, including license counts. Simply scoping access to all people with a NetID (a much wider pool of people than just students and employees) could be a breach of contract. When it comes to vended applications, you can always reach out to the IAM team to help you determine which populations should get access to your application.

On the security side, there are many use-cases where an application should only be accessible to a defined group of users. For instance, you may only want all the people who work within your department to access your departmental intranet. Manifest has Workday and SIS data-driven groups that can help scope to your department only. This is much easier and more secure than manually maintaining an access list or leaving your app open to all of the university.

Getting Started with Access Scoping

There are two primary routes that you can use Manifest to scope access to your applications, a Single Sign On (SSO) integration, or provisioning. By far, most integrations at the UW utilize SSO, but provisioning can be a powerful integration option depending on the application. If you're not sure where to start, send us an email at mstsupport@doit.wisc.edu and we can get you pointed in the right direction.



Keywords:
manifest grouper access single sign on provisioning all students employees data driven eligible 
Doc ID:
163627
Owned by:
Oakes D. in Identity and Access Management
Created:
2026-08-26
Updated:
2026-08-31
Sites:
Identity and Access Management