Preparing to Deploy HYPR Affirm
Use this page to prepare a HYPR Affirm deployment before real requesters use it: work through the checklist, review how document checks can fail and connect the directory source Affirm reads user attributes from.
Solution Deployment Overview
Before deploying HYPR Affirm, work through the following checklist so that the deployment meets your business requirements:
- Identify the Affirm verification flow steps that align with your business requirements
- Determine what the outcome of successful and unsuccessful flows should look like
- Confirm that you have access to HYPR Control Center
- Ask the HYPR deployment team to enable the relevant functionality in your HYPR Control Center (see Affirm Feature Flags)
- Configure your IdP integration or external data source
- Configure your verification flow
For the data retention setting, see Data Retention.
Configuration Tips
IDV Failure Modes
Understand the possible identity verification (IDV) failure modes for document and data validation, such as data comparison, image integrity, visual authenticity, data consistency and age validation. Each breakdown result is clear, consider or empty when the check did not run. The following example shows a document report breakdown.
"breakdown": {
"data_comparison": {
"result": "consider",
"breakdown": {
"first_name": "consider",
"last_name": "consider"
}
},
"data_validation": {
"result": "consider",
"breakdown": {
"gender": "clear",
"date_of_birth": "clear",
"document_numbers": "clear",
"document_expiration": "consider",
"expiry_date": "clear",
"mrz": "",
"barcode": "consider"
}
},
"image_integrity": {
"result": "clear",
"breakdown": {
"image_quality": "clear",
"supported_document": "clear",
"colour_picture": "clear",
"conclusive_document_quality": "clear"
}
},
"visual_authenticity": {
"result": "consider",
"breakdown": {
"fonts": "clear",
"picture_face_integrity": "clear",
"template": "clear",
"security_features": "consider",
"original_document_present": "consider",
"digital_tampering": "clear",
"other": "clear",
"face_detection": "clear"
}
},
"data_consistency": {
"result": "consider",
"breakdown": {
"date_of_expiry": "",
"document_numbers": "consider",
"issuing_country": "",
"document_type": "",
"date_of_birth": "consider",
"gender": "",
"first_name": "consider",
"nationality": "",
"last_name": "consider",
"multiple_data_sources_present": "clear"
}
},
"police_record": {
"result": "",
"breakdown": {}
},
"compromised_document": {
"result": "clear",
"breakdown": {}
},
"age_validation": {
"result": "clear",
"breakdown": {
"minimum_accepted_age": "clear"
}
},
"issuing_authority": {
"result": "",
"breakdown": {
"nfc_active_authentication": "",
"nfc_passive_authentication": ""
}
}
}
Adding an Integration (Directory Source) to HYPR
HYPR Affirm verifies user attributes such as email, phone number and address from a directory source. You can add directory sources through HYPR integration settings or advanced settings.
All target users require a username (UPN for Entra ID, Username for Okta). Other attributes, such as the email address, mobile phone number, first and last name, manager and postal address, are required only by the steps that use them. For the full list with the Entra ID and Okta field names, see Identity-Provider Attribute Requirements and Profile data each step requires.
Adding an Integration (Entra / Okta)
For Entra, configure the Entra tenant first. See Entra ID Integration for steps. When the Entra configuration is complete, configure the integration in HYPR.