Summary
USNH utilizes user roles to provision the basic services that are applicable to most users. This article provides a high-level overview of the user roles and types commonly found in IIQ.
You can also see a table of roles found in IIQ in this spreadsheet: USNH ROLE to ACCOUNT Matrix (Fall 2025).xlsx (requires USNH login to view).
Note: IIQ Roles changed with WorkDay go-live on Dec. 21, 2024.
Primary User Type
To find role information for a user in IIQ, look first at the Biographic / Demographic Data Section of the Attributes Tab in IIQ. While users frequently have multiple ROLES, they have just one Primary User Type. These are the basic definitions and hierarchy:
- Employee: Anyone holding an active, non-student EMPLOYEE role.
- Emeritus: Anyone holding an EMERITUS role and NOT an active, non-student Employee role.
- CWorker: Anyone holding an active CWORKER role and NOT an Employee or Emeritus role.
- Sponsored: Anyone holding an active SPONSORED role and NOT an Employee or Emeritus or CWorker role.
- Student: Anyone holding an active STUDENT role or the STUDEMP role and NOT an Employee or Emeritus or CWorker or Sponsored role
- Prior Student: Anyone holding an ACTIVE UNH PRIOR STUDENT or ACTIVE PSU ALUMNI role and NOT an Employee or Emeritus or CWorker or Sponsored role.
- NoSync: Anyone holding an APPLICANT or ADMIT role or the ESEMP role and NO other active roles. NoSync also includes a cohort of KSC CCSNH people with KSC-CCSNHEMP or KSC-CCSNHSTU roles.
- Empty/null: no active roles, no access - including non-active PRIOR STUDENT or ALUMNI roles
The Primary User Type is a quick way to determine why someone doesn't have accounts. No type, no accounts.
Back to top
Employees
Active Employees
For the most part, anyone who receives a USNH paycheck has an EMPLOYEE role, based on their primary campus, that appears in IIQ as one of:
- KSC-EMPLOYEE
- PSU-EMPLOYEE
- UNH-EMPLOYEE
- USNH-EMPLOYEE
When a user has an EMPLOYEE role you will also see corresponding info about the employee such as their department, primary campus, and supervisor in the Biographic / Demographic Data Section of the Attributes Tab in IIQ.
The EMPLOYEE role ensures that users have access to many services and tools – such as email, M365, VPN, and Workday. In IIQ you may toggle between the Attributes Tab and the Accounts Tab and see the direct correlation to the services that are assigned based on the Employee Role. Here is an example of how a simple employee record looks in IIQ.
Sample Employee record in IIQ:
Employees also have a descriptive Employee role based on their job classification assigned by HR which help to further Identify the user. These are of the form:
[CAMPUS]–[STAGE (INTERIM or SUSPENSE if applicable)]–[ROLE]
For example:
- KSC-FACULTY / KSC-STAFF / KSC-STUDEMP / KSC-ADJUNCTFAC / KSC-ADJUNCTSTAFF / KSC-EXTEDUC (Extension Educator)
- PSU-FACULTY / PSU-STAFF / PSU-STUDEMP / PSU-ADJUNCTFAC / PSU-ADJUNCTSTAFF / PSU-EXTEDUC (Extension Educator)
- UNH-FACULTY / UNH-STAFF / UNH-STUDEMP / UNH-ADJUNCTFAC / UNH-ADJUNCTSTAFF / UNH-EXTEDUC (Extension Educator)
- USNH-STAFF / USNH-STUDEMP / USNH-ADJUNCTSTAFF
Adjunct Faculty and Adjunct Staff positions – Period Activity Pay (PAP)
Adjunct (part-time, seasonal) Faculty & Staff retain an active job role, even during parts of the year when they are not actively working. The Workday function of “Period Activity Pay” manages their access so they have full access during periods when they are working (being paid) and limited (but still active) access during periods when they are not being paid.
- When an adjunct with PAP is in an active pay period, they will hold the full ADJUNCTFAC or ADJUNCTSTAFF role.
- When NOT in an active pay period OR if a future dated pay period has NOT been entered, they will be assigned the SUSPENSE-ADJUNCTFAC or SUSPENSE-ADJUNCTSTAFF role.
- When holding the SUSPENSE role, their M365 license will be downgraded to the A1 license. See details about the different licenses in our Microsoft Licensing FAQ article.
- Employees with SUSPENSE-ADJUNCTFAC/STAFF roles should generally be able to login to the same apps/services as active employees.
- Period Activity Pay replaces “grace periods” for adjunct faculty. When an adjunct faculty or staff member is finally terminated in Workday, their access ends. You can view the user's Employee Status under the Workday Jobs button in the IIQ header.
- Note: The Workday Jobs button in IIQ will not display any expired PAP. Only current and future PAP periods will display in IIQ.
Adjunct Role Summary
| Employee Role |
Definition |
License |
| xx-ADJUNCTFAC |
Adjunct Faculty member actively teaching |
A5 |
| xx-ADJUNCTSTAFF |
Adjunct Staff member actively working |
A5 |
| xx-SUSPENSE-ADJUNCTFAC |
Adjunct Faculty member not actively teaching |
A1 |
| xx-SUSPENSE-ADJUNCTSTAFF |
Adjunct Staff member not actively working |
A1 |
Note:
xx- designates the Campus for that role, e.g. KSC, PSU, UNH, or USNH.
Back to top
Contingent Workers
Contingent workers are people, receiving no pay or benefits from USNH, who need access to USNH systems and resources to do their work.
- All contingent workers are provided with USNH email.
- Some contingent worker types are treated like employees and are provided with similar system access as employees.
Contingent Worker Provisioning
| Contingent Worker Type |
Provisioned Employee-like A5 Access |
| Temp Agency Hire |
Yes |
| Chaplain |
Yes |
| Staff Affiliate |
Yes |
| Academic Affiliate |
Yes |
| Consultant |
No |
| Volunteer |
No |
| Contingent Worker - Finance |
No |
Contingent workers will have a
primary user type of ‘CWorker’ in IIQ.
Anyone holding one of the Contingent Worker roles will also hold a xx-CWorker role, where xx- designates the Campus for that role.
- This is the same as the way anyone holding an employee role (STAFF, FACULTY, etc.) is also assigned the corresponding xx-EMPLOYEE role.
Contingent Worker Role Summary
| Contingent Worker Type |
Contingent Worker Roles |
Definition |
License |
In GAL |
| Temp Agency Hire |
xx-CW-TEMP
xx-CWorker |
Active contingent worker |
A5 |
Yes |
| Temp Agency Hire |
xx-INTERIM-CW-TEMP
xx-INTERIM-CWorker |
Contingent worker with a future dated start date |
A5 |
Yes |
| Chaplain |
xx-CW-CHAP
xx-CWorker |
Active contingent worker |
A5 |
Yes |
| Chaplain |
xx-INTERIM-CW-CHAP
xx-INTERIM-CWorker |
Contingent worker with a future dated start date |
A5 |
Yes |
| Staff Affiliate |
xx-CW-AFFSTAFF
xx-CWorker |
Active contingent worker |
A5 |
Yes |
| Staff Affiliate |
xx-INTERIM-CW-AFFSTAFF
xx-INTERIM-CWorker |
Contingent worker with a future dated start date |
A5 |
Yes |
| Academic Affiliate |
xx-CW-AFFACAD
xx-CWorker |
Active contingent worker |
A5 |
Yes |
| Academic Affiliate |
xx-INTERIM-CW-AFFACAD
xx-INTERIM-CWorker |
Contingent worker with a future dated start date |
A5 |
Yes |
| Consultant |
xx-CW-CONS
xx-CWorker |
Active contingent worker |
A1 |
No |
| Consultant |
xx-INTERIM-CW-CONS
xx-INTERIM-CWorker |
Contingent worker with a future dated start date |
A1 |
No |
| Volunteer |
xx-CW-VOL
xx-CWorker |
Active contingent worker |
A1 |
No |
| Volunteer |
xx-INTERIM-CW-VOL
xx-INTERIM-CWorker |
Contingent worker with a future dated start date |
A1 |
No |
| Contingent Worker - Finance |
xx-CW-FINANCE
xx-CWorker |
Active contingent worker |
A1 |
No |
| Contingent Worker - Finance |
xx-INTERIM-CW-FINANCE
xx-INTERIM-CWorker |
Contingent worker with a future dated start date |
A1 |
No |
Note:
xx- designates the Campus for that role, e.g. KSC, PSU, UNH, or USNH.
Back to top
Emeritus Employees
Certain employees may be granted EMERITUS status when they retire, usually Faculty. This is an Active role which grants that person access to many of the same accounts as when they were an employee. Emeritus employees are licensed to use M365 apps through USNH in the cloud only (A1 license). See special note regarding OneDrive quotas and file access for retiring Emeriti faculty. Emeritus faculty do not retain access to other USNH licensed software such as Adobe express, Qualtrics, or other Academic software titles. Emeritus employees appear in IIQ as one of:
- KSC-EMERITUS
- PSU-EMERITUS
- UNH-EMERITUS
- USNH-EMERITUS
The Emeritus role is an honor conferred by HR on certain retired employees. It is not automatic for most retirees.
Back to top
Grace Periods
Full time Faculty Roles include a 90-day Grace Period after the job termination date. When an employee is in a grace period, these Roles are applied to the user in IIQ:
- KSC-SUSPENSE-FACULTY and KSC-SUSPENSE-EMPLOYEE
- PSU-SUSPENSE-FACULTY and PSU-SUSPENSE-EMPLOYEE
- UNH-SUSPENSE-FACULTY and UNH-SUSPENSE-EMPLOYEE
When a person has the SUSPENSE-FACULTY role, their access to many services remains the same as an active Employee, but they may only have limited or cloud access to some apps and services such as M365. People who only have a SUSPENSE stage role are licensed to use M365 apps through USNH in the cloud only (A1 license). Adobe access is for ACTIVE roles only.
Faculty Role Summary
| Employee Role |
Definition |
License |
| xx-FACULTY |
Full time faculty member who is an active employee |
A5 |
| xx-SUSPENSE-FACULTY |
Full time faculty member who is terminated and in a grace period |
A1 |
Note:
xx- designates the Campus for that role, e.g. KSC, PSU, UNH, or USNH.
At the end of the grace period, they become a regular Terminated Employee. See next section on Terminated Employees.
Back to top
Enhanced Separation (ESEMP) Employees
The ESEMP role identifies former employees who are no longer in a paid position but are receiving some type of benefits. USNH HR controls whether a person has this role or not.
People who have this role are able to log into Workday using SSO. This role does not include access to any other USNH resources.
- For example: people that retire at 62 and continue to receive medical benefits until 65.
- Because they are in an active position in Workday, they need to be able to login to Workday using SSO.
- This is similar to the old WISEACCESS role from 2025.
Anyone holding the ESEMP role who does not have another USNH role will only have access to Workday. They will not be licensed in Entra/M365 nor be able to login to other services like Canvas, etc. If they do have another role, they will retain the access provided by that role.
Back to top
Terminated Employees
When an employee's final job ends in the USNH HR system, unless they have another Active Role that continues to provide services (Student, Alumni, etc.), then their Primary User Type becomes null (empty) and they lose access to all services other than Workday. You can view the user's Employee Status under the Workday Jobs button in the IIQ header.
Terminated Employees with no ESEMP role access Workday through a local Workday account login, not SSO. See related articles:
Back to top
Students
Active Students
Active, currently enrolled students have a Primary Role as STUDENT in IIQ. Those roles appear in IIQ as:
- KSC-STUDENT
- PSU-STUDENT
- UNH-STUDENT
- UNHG-STUDENT - used for students in the UNH College of Professional Studies (UNH CPS) and CPS Online (UNH CPSO), which have some unique business processes
When a user has a STUDENT role you will also see basic info about the student such as their primary campus in the Biographic / Demographic Data Section of the Attributes Tab in IIQ.
The STUDENT role ensures that users have access to many services and tools such as the myUSNH portal, email, M365, VPN, Canvas, etc. In IIQ you may toggle between the Attributes Tab and the Accounts Tab and see the direct correlation to the services that are assigned based on the Student Role. Here is an example of how a simple student record looks in IIQ.
Example student record in IIQ:
Student Off-boarding and R30/R44 processing
Students leaving school retain access to technology resources until about 30 days (PSU & UNH) / 44 days (KSC) into the following Fall or Spring semester after their enrollment ends. The process to remove former students is called the R30/R44 process. The exact date that their access is removed varies by campus schedule - see current dates in IIQ: Campus R30/R44 Process Dates (ETS Internal)
- Note: For the most part, UNH CPS/CPSO students (UNHG-STUDENT role) are not subject to standard R30 processing.
For all other students, the R30/R44 process includes these steps:
- When a student leaves their institution, the campus Registrar's Office marks them as a former student in the student information system (Banner/Colleague). IIQ:
- assigns the (campus)-SUSPENSE-STUDENT informational role and
- retains the existing (campus)-STUDENT role.
- Access to most technology resources remains unchanged, except Adobe access is for ACTIVE roles only.
- About three weeks before R30/R44, IIQ sends notifications to warn them of the coming change to their status.
- The exact R30/R44 date and notification schedule varies by institution.
- IIQ:
- finds everyone holding the (campus)-SUSPENSE-STUDENT role,
- generates a notification to each one,
- removes the (campus)-SUSPENSE-STUDENT role, and
- assigns the (campus)-NOTIFIED-STUDENT role instead.
- After the first notification task runs, we will see PSU-NOTIFIED-STUDENT, UNH-NOTIFIED-STUDENT, and KSC-NOTIFIED-STUDENT roles in IIQ.
- Weekly reminder notifications are also sent by IIQ, with the final notification one business day before the former students lose access.
- Access to technology resources remains unchanged through this notification period.
- On the institution's R30/R44 date, access to most technology resources is removed.
- IIQ finds everyone with the (campus)-NOTIFIED-STUDENT role, removes the (campus)-NOTIFIED-STUDENT role, and removes the (campus)-STUDENT role.
- Then there is still variation by institution:
- PSU & UNH – Assign nothing. If the user holds the PSU(UNH)-ACTIVE-ALUMNI and PSU(UNH)-ALUMNI role, they retain access. Assignment of PSU(UNH)-ALUMNI role is from PSU/UNH Registrar's Office. PSU(UNH)-ACTIVE-ALUMNI retain access to email only, as long as password is in compliance. For non-alumni or expired passwords, access is removed.
- KSC – Assign nothing. Access is removed.
There is a record of each notification in the Notification History in IIQ.
- Definition of NOTIFIED-STUDENT role. Basically, it means the student will be converted within the next 3 weeks or so to their non-student role. Student access does not change with the NOTIFIED-STUDENT role.
- Requests for exception – No. 😊
- If a student requests an extension, the answer is no.
- If they need help downloading content, etc., they can get help at one of the walk-up locations or by phone or remote session.
- If they think they should be classified as a student, they need to talk to their respective campus Registrar’s Office.
Back to top
Alumni & grandfathered UNH Prior Students
When Students graduate from their institution, they are given a PRIMARY ALUMNI Role. However, each institution treats these departed students differently. Note that only the ACTIVE versions of these roles give former students email access according to campus policies.
|
Institution
|
Former Student Roles
|
Services Provided
|
|
Keene
|
No Roles
|
No Services
|
|
Plymouth
|
If left the institution (no Grad) -> no IIQ role
|
No Services
|
|
If they Graduated -> PSU-ALUMNI
If PW is current (Not expired) they initially also get PSU-ACTIVE-ALUMNI
|
PSU Email ONLY, no portal access
|
|
If they Graduated -> PSU-ALUMNI
If PW is expired, PSU-ACTIVE-ALUMNI is removed 120 days after the PW expires.
|
Email is purged – no recovery available
|
|
UNH
|
If left the institution (no Grad) -> no IIQ role
|
No Services
|
|
If they Graduated -> UNH-ALUMNI
If PW is current (Not expired) they initially also get UNH-ACTIVE-ALUMNI
|
UNH Email ONLY, no portal access
|
|
If they Graduated -> UNH-ALUMNI
If PW is expired, UNH-ACTIVE-ALUMNI is removed 120 days after the PW expires.
|
Email is purged – no recovery available
|
|
If Prior Student* - > UNH-PRIOR-STUDENT
If PW is current (Not expired) they also get UNH-ACTIVE-PRIOR-STUDENT
|
UNH Email ONLY, no portal access |
|
If Prior Student* - > UNH-PRIOR-STUDENT
If PW is expired, UNH-ACTIVE-PRIOR-STUDENT is removed 120 days after the PW expires.
|
Email is purged – no recovery available
|
* UNH Prior Students as of May 2024 were “grandfathered” into this role. No new PRIOR-STUDENT roles assigned after May 2024. Once a UNH-PRIOR-STUDENT role is purged, it cannot be re-assigned.
Back to top
Sponsored Users / Friends
Some users have a role of SPONSORED or (at PSU) PSU-FRIEND. This will appear in IIQ as one of:
- KSC-SPONSORED
- PSU-FRIEND
- UNH-SPONSORED
- USNH-SPONSORED
This Role is given to users who have a short-term affiliation with a USNH institution. While the user is neither an employee nor a student, their access often mimics that of an employee or student. This Role type is used for vendors, external contractors, and researchers who may need to collaborate with USNH teams. Sponsored Users (Friends) have access for less than 365 days and their sponsorship must be renewed by their supervisor annually.
Sponsored users will not be able to access the M365 Desktop apps due to the licensing changes from March 2024. They will have access to the online versions.
It is fairly common just before start of an academic semester for a handful of Sponsored users to lose their access and for the Help Desk to get a call about that lost access. You can verify that the Role was removed from a user by looking in the Role History tab – where you can see the date of the role removal. There is no Grace period for these users.
The Help Desk CANNOT renew the sponsorship for the user. The user may not make a request for themselves. At UNH, USNH, and KSC, the supervisor will need to use the UNH Accounts Management System (AMS) to request a renewal of their person’s sponsorship. At PSU, the request is processed by the Help Desk, but the request must be submitted by the Supervisor and the ticket escalated to the PSU Help Desk team.
Back to top
Further Readings
myUSNH Portal: Access is Role Based (ETS Internal)
IIQ: Campus R30/R44 Process Dates (ETS Internal)
FAQs for Graduating and Departing Students
Canvas (myCourses): What happens to my access when I leave the institution?
USNH Accounts: Employee Account Deactivation
Microsoft Licensing: M365 License Change effective March 2024
OneDrive: Moving Institutional Files to SharePoint before leaving USNH - for USNH owned/shared data
OneDrive: Copying Personal Files/Folders before Leaving the University
USNH ROLE to ACCOUNT Matrix (Fall 2025).xlsx - USNH Sharepoint (requires USNH login to view)
UNH Accounts Management System (AMS)
Workday: IIQ and Role Changes (ETS Internal) - effective Dec. 21, 2024
Need additional help?
If you have questions or need additional help with these topics, please reach out to your Team Lead or supervisor for assistance.
The Group: ET&S CN - IAM Identity & Access Systems owns the IIQ tool.