I'd just use .htpasswd authentication on the forum directory; then users can have their own "forum access" password, and forum account; or you could use a "forum password" using htpassd and just have it so that it's a genaric user/pass and only let employees know the password...
You could additionally require login on every forum, then turn on the registration queue and only approve those who should be approbed as well...