Get Started with HYPR Affirm
This tutorial walks a new administrator through running their first HYPR Affirm verification flow end to end: creating a workflow in Control Center, observing the requester experience and reviewing the outcome in the Activity Log.
The tutorial scenario is employee onboarding through Entra ID: an employee completes identity verification before being issued their first authentication method. It exercises a broad set of Affirm capabilities.
For the model behind flows, steps and outcomes, read The Verification Model first.
Prerequisites
Before starting, confirm the following:
- HYPR has enabled HYPR Affirm on the tenant. If you don't see the Affirm tab in Control Center, contact your HYPR representative to confirm tenant enablement.
- A Microsoft Entra ID integration is configured in HYPR Control Center for the application your verification flow protects. See Integrations.
- A test user exists in Entra ID with the directory attributes Affirm requires:
UPN(user principal name), email address, mobile phone for the one-time password (OTP), and manager assignment if you use a manager-based approver. - You have an alternative phone, email and government-issued document on hand for completing the requester walkthrough yourself.
Open the Workflow Editor
In Control Center, click HYPR Affirm in the left navigation menu. Open the Verification Flows tab if it isn't already active.
Create Your First Verification Flow
- Click + Verification Flow at the top right. The New Verification Flow dialog opens.
- Enter a Name for the flow, for example Employee Onboarding Quickstart.
- Optional: Enter a Description.
- In Type, select Onboarding.
- Click + Verification Flow to save. Control Center opens your new flow in the workflow editor, with the General tab in view and a left sidebar listing every configurable section.
For details on the workflow types and the columns shown in the flow list, see Create and Manage Verification Flows.
Configure Verification Steps
In the workflow editor's left sidebar, select Verification Steps.
For this tutorial, enable a minimal but realistic set of steps:
- Instructions, Consent and Login Identifier: always required and always enabled.
- Phone Number / Email Verification: keep enabled (the default).
- Document and Biometric Verification: enable it. This step demonstrates Affirm's document and face checks. Inside the step, enable both Document Authentication and Liveness Check.
- Attestation: leave it turned off. Attestation requires a human approver, and this tutorial uses automated approval.
Leave the other steps at their defaults.
For details on each step type, see Configure Verification Steps.
Assign an Approver
In the workflow editor's left sidebar, select Primary Approvers. A new flow already lists HYPR (automated approval) as its approver; keep it. If it is not listed, click Add Approver and choose HYPR (automated approval). Affirm approves or denies based on whether all enabled verification steps pass, so you can complete the tutorial without coordinating with a human reviewer.
For a flow with human review, choose Manager, Other (a custom email) or Dynamic, and set a Timeout. See Approvers and Escalation Approvers.
Set the Outcome
Open the Verified Outcome section of the workflow. Select Redirect to Device Manager to register a new login method, then choose the application in Associated RP App ID. This sends a successful requester to HYPR's Device Manager to register their first authentication device.
For Entra Temporary Access Pass, Entra Verified ID, or Okta password reset outcomes, see Outcomes and Integration.
Activate, Save and Copy the Flow URL
A new flow starts Inactive, and a requester who opens an inactive flow sees Invalid configuration.
- At the top of the workflow editor, next to the flow name, turn on the Active switch.
- Click Save at the top right of the editor.
- Click Back to Verification Flows.
- In the Verification Flows list, click the copy icon in the URL column for your new flow. You give this URL to the requester, or an integration invokes it on the requester's behalf.
Run the Flow as the Requester
In a separate browser (or incognito window), paste the URL and complete the verification yourself as the requester.
-
Read the instructions and click Continue.
-
Scroll through the consent content and click Accept.
-
Enter the test user's login identifier (UPN) and click Begin.
-
Confirm the phone or email OTP.
-
Capture the front of the document, and the back if applicable.
-
Take the live selfie.
-
Wait while Affirm evaluates the results.
-
Continue to the Device Manager outcome screen.
For details on what the requester sees at each step, see What the Requester Sees.
Review the Outcome in the Activity Log
Back in Control Center, click HYPR Affirm → Activity Log. Your test run appears at the top. Click the row to open its details and see:
- The decision (Verified or Unverified) and the workflow status (see Verification Status Values)
- The Workflow ID that ties this run to events, the Audit Trail and API responses
- Per-step outcomes for phone, document and liveness
- The evidence package (document captures, selfie), if your tenant retains them under the Data Retention setting
For the full Activity Log field reference, see Activity Log.
Next Steps
Now that you've run a verification end to end, continue with these tasks:
- Configure a production workflow — repeat this tutorial with real approvers, retry limits and outcome gating, as described in Injectable Outcomes & Retry Limits
- Add policy controls — restrict where requesters can verify from with Network and Location Policy
- Customize the end-user screens — apply branding kits in Affirm Studio
- Configure the Helpdesk — enable agent-initiated verification flows with Affirm Helpdesk
- Integrate with downstream systems — push verification images to enterprise directories with Directory Image Writeback