Skip to main content
Version: 11.3.0

Get Started with HYPR Affirm

This tutorial walks a new administrator through running their first HYPR Affirm verification flow end to end: creating a workflow in Control Center, observing the requester experience and reviewing the outcome in the Activity Log.

The tutorial scenario is employee onboarding through Entra ID: an employee completes identity verification before being issued their first authentication method. It exercises a broad set of Affirm capabilities.

For the model behind flows, steps and outcomes, read The Verification Model first.

Prerequisites​

Before starting, confirm the following:

  • HYPR has enabled HYPR Affirm on the tenant. If you don't see the Affirm tab in Control Center, contact your HYPR representative to confirm tenant enablement.
  • A Microsoft Entra ID integration is configured in HYPR Control Center for the application your verification flow protects. See Integrations.
  • A test user exists in Entra ID with the directory attributes Affirm requires: UPN (user principal name), email address, mobile phone for the one-time password (OTP), and manager assignment if you use a manager-based approver.
  • You have an alternative phone, email and government-issued document on hand for completing the requester walkthrough yourself.

Open the Workflow Editor​

In Control Center, click HYPR Affirm in the left navigation menu. Open the Verification Flows tab if it isn't already active.

HYPR Control Center left navigation menu with HYPR Affirm selected HYPR Affirm page with the Verification Flows tab active, showing the flow list and the Verification Flow button

Create Your First Verification Flow​

  1. Click + Verification Flow at the top right. The New Verification Flow dialog opens.
  2. Enter a Name for the flow, for example Employee Onboarding Quickstart.
  3. Optional: Enter a Description.
  4. In Type, select Onboarding.
  5. Click + Verification Flow to save. Control Center opens your new flow in the workflow editor, with the General tab in view and a left sidebar listing every configurable section.
New Verification Flow dialog with empty Name, Description and Type fields and the Verification Flow button Verification Flows tab listing an inactive Onboarding flow with its name, type, URL, description and status

For details on the workflow types and the columns shown in the flow list, see Create and Manage Verification Flows.

Configure Verification Steps​

In the workflow editor's left sidebar, select Verification Steps.

For this tutorial, enable a minimal but realistic set of steps:

  • Instructions, Consent and Login Identifier: always required and always enabled.
  • Phone Number / Email Verification: keep enabled (the default).
  • Document and Biometric Verification: enable it. This step demonstrates Affirm's document and face checks. Inside the step, enable both Document Authentication and Liveness Check.
  • Attestation: leave it turned off. Attestation requires a human approver, and this tutorial uses automated approval.

Leave the other steps at their defaults.

Workflow editor with the General section open and the left sidebar listing Verification Steps such as Consent and Attestation

For details on each step type, see Configure Verification Steps.

Assign an Approver​

In the workflow editor's left sidebar, select Primary Approvers. A new flow already lists HYPR (automated approval) as its approver; keep it. If it is not listed, click Add Approver and choose HYPR (automated approval). Affirm approves or denies based on whether all enabled verification steps pass, so you can complete the tutorial without coordinating with a human reviewer.

Approver Assignment section with the Add Approver button and the Assigned Approvers list

For a flow with human review, choose Manager, Other (a custom email) or Dynamic, and set a Timeout. See Approvers and Escalation Approvers.

Set the Outcome​

Open the Verified Outcome section of the workflow. Select Redirect to Device Manager to register a new login method, then choose the application in Associated RP App ID. This sends a successful requester to HYPR's Device Manager to register their first authentication device.

Outcome section with the Outcome API Call dropdown set to No Customization

For Entra Temporary Access Pass, Entra Verified ID, or Okta password reset outcomes, see Outcomes and Integration.

Activate, Save and Copy the Flow URL​

A new flow starts Inactive, and a requester who opens an inactive flow sees Invalid configuration.

  1. At the top of the workflow editor, next to the flow name, turn on the Active switch.
  2. Click Save at the top right of the editor.
  3. Click Back to Verification Flows.
  4. In the Verification Flows list, click the copy icon in the URL column for your new flow. You give this URL to the requester, or an integration invokes it on the requester's behalf.
Verification Flows list with each flow URL and its copy icon

Run the Flow as the Requester​

In a separate browser (or incognito window), paste the URL and complete the verification yourself as the requester.

Let's get started screen with a username or email field filled in and the Begin button
  1. Read the instructions and click Continue.

  2. Scroll through the consent content and click Accept.

  3. Enter the test user's login identifier (UPN) and click Begin.

  4. Confirm the phone or email OTP.

    Let's verify your phone screen asking for the phone number on file, with the Next button
  5. Capture the front of the document, and the back if applicable.

    One final step screen showing Document and Selfie uploaded, with the Submit verification button
  6. Take the live selfie.

    Take a selfie screen with face-forward and glasses guidance and the Take selfie button
  7. Wait while Affirm evaluates the results.

  8. Continue to the Device Manager outcome screen.

    Device Manager Login Methods page showing No Login Methods Found and the Add New Login Method button

For details on what the requester sees at each step, see What the Requester Sees.

Review the Outcome in the Activity Log​

Back in Control Center, click HYPR Affirm → Activity Log. Your test run appears at the top. Click the row to open its details and see:

  • The decision (Verified or Unverified) and the workflow status (see Verification Status Values)
  • The Workflow ID that ties this run to events, the Audit Trail and API responses
  • Per-step outcomes for phone, document and liveness
  • The evidence package (document captures, selfie), if your tenant retains them under the Data Retention setting
Activity Log tab listing verification runs with Workflow ID, Date and Time, Requester and Verified or Unverified decisions Activity Log details for one run, showing a Verified decision, the Workflow ID, timing and a Completed status

For the full Activity Log field reference, see Activity Log.

Next Steps​

Now that you've run a verification end to end, continue with these tasks: