IIQ: Overview of USNH User Roles & Types (ETS Internal)

Summary

USNH utilizes user roles to provision the basic services that are applicable to most users. This article provides a high-level overview of the user roles and types commonly found in IIQ.

Body

Summary

USNH utilizes user roles to provision the basic services that are applicable to most users. This article provides a high-level overview of the user roles and types commonly found in IIQ. 

You can also see a table of roles found in IIQ in this spreadsheet: USNH ROLE to ACCOUNT Matrix (Fall 2025).xlsx (requires USNH login to view).

Note: IIQ Roles changed with WorkDay go-live on Dec. 21, 2024. 

 

Primary User Type

To find role information for a user in IIQ, look first at the Biographic / Demographic Data Section of the Attributes Tab in IIQ.  While users frequently have multiple ROLES, they have just one Primary User Type.  These are the basic definitions and hierarchy:

  • Employee:  Anyone holding an active, non-student EMPLOYEE role.
  • Emeritus:  Anyone holding an EMERITUS role and NOT an active, non-student Employee role.
  • CWorker:  Anyone holding an active CWORKER role and NOT an Employee or Emeritus role.
  • Sponsored:  Anyone holding an active SPONSORED role and NOT an Employee or Emeritus or CWorker role.
  • Student:  Anyone holding an active STUDENT role or the STUDEMP role and NOT an Employee or Emeritus or CWorker or Sponsored role
  • Prior Student:  Anyone holding an ACTIVE UNH PRIOR STUDENT or ACTIVE PSU ALUMNI role and NOT an Employee or Emeritus or CWorker or Sponsored role.
  • NoSync:  Anyone holding an APPLICANT or ADMIT role or the ESEMP role and NO other active roles.  NoSync also includes a cohort of KSC CCSNH people with KSC-CCSNHEMP or KSC-CCSNHSTU roles.
  • Empty/null:  no active roles, no access - including non-active PRIOR STUDENT or ALUMNI roles

The Primary User Type is a quick way to determine why someone doesn't have accounts.  No type, no accounts.

Back to top

 

Employees

Active Employees

For the most part, anyone who receives a USNH paycheck has an EMPLOYEE role, based on their primary campus, that appears in IIQ as one of:

  • KSC-EMPLOYEE 
  • PSU-EMPLOYEE 
  • UNH-EMPLOYEE 
  • USNH-EMPLOYEE 

When a user has an EMPLOYEE role you will also see corresponding info about the employee such as their department, primary campus, and supervisor in the Biographic / Demographic Data Section of the Attributes Tab in IIQ

The EMPLOYEE role ensures that users have access to many services and tools – such as email, M365, VPN, and Workday.   In IIQ you may toggle between the Attributes Tab and the Accounts Tab and see the direct correlation to the services that are assigned based on the Employee Role.  Here is an example of how a simple employee record looks in IIQ. 

Sample Employee record in IIQ:
Sample Employee record in IIQ 

Employees also have a descriptive Employee role based on their job classification assigned by HR which help to further Identify the user. These are of the form:

[CAMPUS]–[STAGE (INTERIM or SUSPENSE if applicable)]–[ROLE]

For example: 

  • KSC-FACULTY / KSC-STAFF / KSC-STUDEMP / KSC-ADJUNCTFAC / KSC-ADJUNCTSTAFF / KSC-EXTEDUC (Extension Educator)
  • PSU-FACULTY / PSU-STAFF / PSU-STUDEMP / PSU-ADJUNCTFAC / PSU-ADJUNCTSTAFF / PSU-EXTEDUC (Extension Educator)
  • UNH-FACULTY / UNH-STAFF / UNH-STUDEMP / UNH-ADJUNCTFAC / UNH-ADJUNCTSTAFF / UNH-EXTEDUC (Extension Educator)
  • USNH-STAFF / USNH-STUDEMP / USNH-ADJUNCTSTAFF 

 

Adjunct Faculty and Adjunct Staff positions – Period Activity Pay (PAP) 

Adjunct (part-time, seasonal) Faculty & Staff retain an active job role, even during parts of the year when they are not actively working.  The Workday function of “Period Activity Pay” manages their access so they have full access during periods when they are working (being paid) and limited (but still active) access during periods when they are not being paid. 

  • When an adjunct with PAP is in an active pay period, they will hold the full ADJUNCTFAC or ADJUNCTSTAFF role.    
  • When NOT in an active pay period OR if a future dated pay period has NOT been entered, they will be assigned the SUSPENSE-ADJUNCTFAC or SUSPENSE-ADJUNCTSTAFF role.   
    • When holding the SUSPENSE role, their M365 license will be downgraded to the A1 license. See details about the different licenses in our Microsoft Licensing FAQ article.  
    • Employees with SUSPENSE-ADJUNCTFAC/STAFF roles should generally be able to login to the same apps/services as active employees. 
  • Period Activity Pay replaces “grace periods” for adjunct faculty. When an adjunct faculty or staff member is finally terminated in Workday, their access ends. You can view the user's Employee Status under the Workday Jobs button in the IIQ header.
    • Note: The Workday Jobs button in IIQ will not display any expired PAP.   Only current and future PAP periods will display in IIQ.
Adjunct Role Summary
Employee Role Definition License
xx-ADJUNCTFAC Adjunct Faculty member actively teaching A5
xx-ADJUNCTSTAFF Adjunct Staff member actively working A5
xx-SUSPENSE-ADJUNCTFAC Adjunct Faculty member not actively teaching A1
xx-SUSPENSE-ADJUNCTSTAFF Adjunct Staff member not actively working A1
Note: xx- designates the Campus for that role, e.g. KSC, PSU, UNH, or USNH.

Back to top

 

Contingent Workers 

Contingent workers are people, receiving no pay or benefits from USNH, who need access to USNH systems and resources to do their work.

  • All contingent workers are provided with USNH email.
  • Some contingent worker types are treated like employees and are provided with similar system access as employees.
Contingent Worker Provisioning
Contingent Worker Type Provisioned Employee-like A5 Access
Temp Agency Hire Yes
Chaplain Yes
Staff Affiliate Yes
Academic Affiliate Yes
Consultant No
Volunteer No
Contingent Worker - Finance No
Contingent workers will have a primary user type of ‘CWorker’ in IIQ. 

Anyone holding one of the Contingent Worker roles will also hold a xx-CWorker role, where xx- designates the Campus for that role.  

  • This is the same as the way anyone holding an employee role (STAFF, FACULTY, etc.) is also assigned the corresponding xx-EMPLOYEE role. 
Contingent Worker Role Summary
Contingent Worker Type Contingent Worker Roles Definition License In GAL
Temp Agency Hire xx-CW-TEMP
xx-CWorker
Active contingent worker A5 Yes
Temp Agency Hire xx-INTERIM-CW-TEMP
xx-INTERIM-CWorker
Contingent worker with a future dated start date A5 Yes
Chaplain xx-CW-CHAP
xx-CWorker
Active contingent worker A5 Yes
Chaplain xx-INTERIM-CW-CHAP
xx-INTERIM-CWorker
Contingent worker with a future dated start date A5 Yes
Staff Affiliate xx-CW-AFFSTAFF
xx-CWorker
Active contingent worker A5 Yes
Staff Affiliate xx-INTERIM-CW-AFFSTAFF
xx-INTERIM-CWorker
Contingent worker with a future dated start date A5 Yes
Academic Affiliate xx-CW-AFFACAD
xx-CWorker
Active contingent worker A5 Yes
Academic Affiliate xx-INTERIM-CW-AFFACAD
xx-INTERIM-CWorker
Contingent worker with a future dated start date A5 Yes
Consultant xx-CW-CONS
xx-CWorker
Active contingent worker A1 No
Consultant xx-INTERIM-CW-CONS
xx-INTERIM-CWorker
Contingent worker with a future dated start date A1 No
Volunteer xx-CW-VOL
xx-CWorker
Active contingent worker A1 No
Volunteer xx-INTERIM-CW-VOL
xx-INTERIM-CWorker
Contingent worker with a future dated start date A1 No
Contingent Worker - Finance xx-CW-FINANCE
xx-CWorker
Active contingent worker A1 No
Contingent Worker - Finance xx-INTERIM-CW-FINANCE
xx-INTERIM-CWorker
Contingent worker with a future dated start date A1 No
Note: xx- designates the Campus for that role, e.g. KSC, PSU, UNH, or USNH.

Back to top

 

Emeritus Employees

Certain employees may be granted EMERITUS status when they retire, usually Faculty.  This is an Active role which grants that person access to many of the same accounts as when they were an employee.  Emeritus employees are licensed to use M365 apps through USNH in the cloud only (A1 license). See special note regarding OneDrive quotas and file access for retiring Emeriti faculty.  Emeritus faculty do not retain access to other USNH licensed software such as Adobe express, Qualtrics, or other Academic software titles.  Emeritus employees appear in IIQ as one of:

  • KSC-EMERITUS
  • PSU-EMERITUS
  • UNH-EMERITUS
  • USNH-EMERITUS

The Emeritus role is an honor conferred by HR on certain retired employees.  It is not automatic for most retirees.

Back to top

 

Grace Periods

Full time Faculty Roles include a 90-day Grace Period after the job termination date. When an employee is in a grace period, these Roles are applied to the user in IIQ: 

  • KSC-SUSPENSE-FACULTY and KSC-SUSPENSE-EMPLOYEE
  • PSU-SUSPENSE-FACULTY and PSU-SUSPENSE-EMPLOYEE
  • UNH-SUSPENSE-FACULTY and UNH-SUSPENSE-EMPLOYEE

When a person has the SUSPENSE-FACULTY role, their access to many services remains the same as an active Employee, but they may only have limited or cloud access to some apps and services such as M365.  People who only have a SUSPENSE stage role are licensed to use M365 apps through USNH in the cloud only (A1 license). Adobe access is for ACTIVE roles only.

Faculty Role Summary
Employee Role Definition License
xx-FACULTY Full time faculty member who is an active employee A5
xx-SUSPENSE-FACULTY Full time faculty member who is terminated and in a grace period A1
Note: xx- designates the Campus for that role, e.g. KSC, PSU, UNH, or USNH.

At the end of the grace period, they become a regular Terminated Employee. See next section on Terminated Employees.

Back to top 

 

Enhanced Separation (ESEMP) Employees

The ESEMP role identifies former employees who are no longer in a paid position but are receiving some type of benefits. USNH HR controls whether a person has this role or not.

People who have this role are able to log into Workday using SSO. This role does not include access to any other USNH resources. 

  • For example: people that retire at 62 and continue to receive medical benefits until 65.  
  • Because they are in an active position in Workday, they need to be able to login to Workday using SSO. 
  • This is similar to the old WISEACCESS role from 2025.

Anyone holding the ESEMP role who does not have another USNH role will only have access to Workday.  They will not be licensed in Entra/M365 nor be able to login to other services like Canvas, etc.  If they do have another role, they will retain the access provided by that role.

Back to top 

 

Terminated Employees

When an employee's final job ends in the USNH HR system, unless they have another Active Role that continues to provide services (Student, Alumni, etc.), then their Primary User Type becomes null (empty) and they lose access to all services other than Workday.  You can view the user's Employee Status under the Workday Jobs button in the IIQ header.

Terminated Employees with no ESEMP role access Workday through a local Workday account login, not SSO. See related articles:

Back to top

 

Students

Active Students

Active, currently enrolled students have a Primary Role as STUDENT in IIQ.  Those roles appear in IIQ as: 

  • KSC-STUDENT
  • PSU-STUDENT
  • UNH-STUDENT
  • UNHG-STUDENT - used for students in the UNH College of Professional Studies (UNH CPS) and CPS Online (UNH CPSO), which have some unique business processes

When a user has a STUDENT role you will also see basic info about the student such as their primary campus in the Biographic / Demographic Data Section of the Attributes Tab in IIQ.  

The STUDENT role ensures that users have access to many services and tools such as the myUSNH portal, email, M365, VPN, Canvas, etc.  In IIQ you may toggle between the Attributes Tab and the Accounts Tab and see the direct correlation to the services that are assigned based on the Student Role.  Here is an example of how a simple student record looks in IIQ. 

Example student record in IIQ:
A screenshot of a computerDescription automatically generated 

 

Student Off-boarding and R30/R44 processing

Students leaving school retain access to technology resources until about 30 days (PSU & UNH) / 44 days (KSC) into the following Fall or Spring semester after their enrollment ends. The process to remove former students is called the R30/R44 process.  The exact date that their access is removed varies by campus schedule - see current dates in IIQ: Campus R30/R44 Process Dates (ETS Internal) 

  • Note: For the most part, UNH CPS/CPSO students (UNHG-STUDENT role) are not subject to standard R30 processing.

For all other students, the R30/R44 process includes these steps:

  • When a student leaves their institution, the campus Registrar's Office marks them as a former student in the student information system (Banner/Colleague).  IIQ: 
    • assigns the (campus)-SUSPENSE-STUDENT informational role and
    • retains the existing (campus)-STUDENT role. 
    • Access to most technology resources remains unchanged, except Adobe access is for ACTIVE roles only.
  • About three weeks before R30/R44, IIQ sends notifications to warn them of the coming change to their status. 
    • The exact R30/R44 date and notification schedule varies by institution.  
    • IIQ:
      • finds everyone holding the (campus)-SUSPENSE-STUDENT role,
      • generates a notification to each one,
      • removes the (campus)-SUSPENSE-STUDENT role, and
      • assigns the (campus)-NOTIFIED-STUDENT role instead. 
    • After the first notification task runs, we will see PSU-NOTIFIED-STUDENT, UNH-NOTIFIED-STUDENT, and KSC-NOTIFIED-STUDENT roles in IIQ. 
    • Weekly reminder notifications are also sent by IIQ, with the final notification one business day before the former students lose access.
    • Access to technology resources remains unchanged through this notification period.
  • On the institution's R30/R44 date, access to most technology resources is removed. 
    • IIQ finds everyone with the (campus)-NOTIFIED-STUDENT role, removes the (campus)-NOTIFIED-STUDENT role, and removes the (campus)-STUDENT role. 
    • Then there is still variation by institution:
      • PSU & UNH – Assign nothing.  If the user holds the PSU(UNH)-ACTIVE-ALUMNI and PSU(UNH)-ALUMNI role, they retain access.   Assignment of PSU(UNH)-ALUMNI role is from PSU/UNH Registrar's Office.  PSU(UNH)-ACTIVE-ALUMNI retain access to email only, as long as password is in compliance.  For non-alumni or expired passwords, access is removed.
      • KSC – Assign nothing.   Access is removed.

There is a record of each notification in the Notification History in IIQ.   

  • Definition of NOTIFIED-STUDENT role.   Basically, it means the student will be converted within the next 3 weeks or so to their non-student role.  Student access does not change with the NOTIFIED-STUDENT role.
  • Requests for exception – No.  ðŸ˜Š 
    • If a student requests an extension, the answer is no. 
    • If they need help downloading content, etc., they can get help at one of the walk-up locations or by phone or remote session.   
    • If they think they should be classified as a student, they need to talk to their respective campus Registrar’s Office. 

Back to top

 

Alumni & grandfathered UNH Prior Students

When Students graduate from their institution, they are given a PRIMARY ALUMNI Role.  However, each institution treats these departed students differently.  Note that only the ACTIVE versions of these roles give former students email access according to campus policies. 

Institution 

Former Student Roles 

Services Provided 

Keene 

No Roles

No Services 

Plymouth 

If left the institution (no Grad) -> no IIQ role

No Services 

If they Graduated -> PSU-ALUMNI

If PW is current (Not expired) they initially also get PSU-ACTIVE-ALUMNI

PSU Email ONLY, no portal access 

If they Graduated -> PSU-ALUMNI

If PW is expired, PSU-ACTIVE-ALUMNI is removed 120 days after the PW expires. 

Email is purged – no recovery available 

UNH 

If left the institution (no Grad) -> no IIQ role

No Services 

If they Graduated -> UNH-ALUMNI

If PW is current (Not expired) they initially also get UNH-ACTIVE-ALUMNI

UNH Email ONLY, no portal access

If they Graduated -> UNH-ALUMNI

If PW is expired, UNH-ACTIVE-ALUMNI is removed 120 days after the PW expires.

Email is purged – no recovery available

If Prior Student* - > UNH-PRIOR-STUDENT

If PW is current (Not expired) they also get UNH-ACTIVE-PRIOR-STUDENT


UNH Email ONLY, no portal access

If Prior Student* - > UNH-PRIOR-STUDENT

If PW is expired, UNH-ACTIVE-PRIOR-STUDENT is removed 120 days after the PW expires. 

Email is purged – no recovery available 

* UNH Prior Students as of May 2024 were “grandfathered” into this role. No new PRIOR-STUDENT roles assigned after May 2024. Once a UNH-PRIOR-STUDENT role is purged, it cannot be re-assigned.

Back to top

 

Sponsored Users / Friends

Some users have a role of SPONSORED or (at PSU) PSU-FRIEND. This will appear in IIQ as one of:

  • KSC-SPONSORED
  • PSU-FRIEND
  • UNH-SPONSORED
  • USNH-SPONSORED

This Role is given to users who have a short-term affiliation with a USNH institution.  While the user is neither an employee nor a student, their access often mimics that of an employee or student.  This Role type is used for vendors, external contractors, and researchers who may need to collaborate with USNH teams.    Sponsored Users (Friends) have access for less than 365 days and their sponsorship must be renewed by their supervisor annually. 

Sponsored users will not be able to access the M365 Desktop apps due to the licensing changes from March 2024. They will have access to the online versions.

It is fairly common just before start of an academic semester for a handful of Sponsored users to lose their access and for the Help Desk to get a call about that lost access.  You can verify that the Role was removed from a user by looking in the Role History tab – where you can see the date of the role removal.  There is no Grace period for these users. 

The Help Desk CANNOT renew the sponsorship for the user. The user may not make a request for themselves.   At UNH, USNH, and KSC, the supervisor will need to use the UNH Accounts Management System (AMS)  to request a renewal of their person’s sponsorship.  At PSU, the request is processed by the Help Desk, but the request must be submitted by the Supervisor and the ticket escalated to the PSU Help Desk team. 

Back to top

 

Further Readings

myUSNH Portal: Access is Role Based (ETS Internal)

IIQ: Campus R30/R44 Process Dates (ETS Internal)

FAQs for Graduating and Departing Students

Canvas (myCourses): What happens to my access when I leave the institution?

USNH Accounts: Employee Account Deactivation

Microsoft Licensing: M365 License Change effective March 2024 

OneDrive: Moving Institutional Files to SharePoint before leaving USNH - for USNH owned/shared data

OneDrive: Copying Personal Files/Folders before Leaving the University

USNH ROLE to ACCOUNT Matrix (Fall 2025).xlsx    - USNH Sharepoint (requires USNH login to view)

UNH Accounts Management System (AMS)  

Workday: IIQ and Role Changes (ETS Internal) - effective Dec. 21, 2024

 

Need additional help?

If you have questions or need additional help with these topics, please reach out to your Team Lead or supervisor for assistance.

The Group: ET&S CN - IAM Identity & Access Systems owns the IIQ tool.

 

Details

Details

Article ID: 4773
Created
Wed 8/30/23 3:37 PM
Modified
Tue 7/28/26 5:13 PM
Applicable Institution(s):
Keene State College (KSC)
Plymouth State University (PSU)
University of New Hampshire (UNH)
USNH System Office