HYPR Affirm Helpdesk Support
Overview
HYPR Affirm Helpdesk Support brings secure, auditable identity verification to enterprise support teams. For real-time workforce assistance, it provides a dedicated Helpdesk portal, user management workflows and deployment controls.
Help desk interactions that rely on manual, insecure methods to verify user identity create security gaps and compliance risks. HYPR Affirm Helpdesk Support gives support teams a secure, consistent way to verify users during password resets, access escalations and support escalations.
Key Benefits
Helpdesk Support offers the following benefits:
- Strengthen security during human-assisted authentication workflows.
- Keep a record of each Helpdesk-initiated verification and the agent who initiated it. For how HYPR handles data, see the HYPR Privacy Policy.
- Improve agent efficiency through fast, intuitive verification-code workflows.
- Streamline management of support verification policies at scale.
Capabilities
HYPR Affirm Helpdesk Support provides the following identity verification capabilities for enterprise support teams:
- Helpdesk Portal Access: Secure login through existing authentication methods (SSO, enterprise identity providers) with role-based access controls
- Verification Flow Management: View and initiate verification sessions with the workflow initialization modal
- Dynamic Workflow Invocation: Input user attributes (login identifier, name, email, phone) to trigger verification sessions for users not yet in the system
- Multi-Channel Delivery: Send verification links by email or SMS, or copy them to the clipboard for custom channels (internal chat, ticketing platforms)
- Verification Results Management: A results table, verification code search, detailed result views and verification code validation
- Audit Records: Helpdesk-initiated workflows are recorded like any other workflow; see Audit Trail
- Real-time Identity Verification: Proactive workflow initiation for access issues, sensitive support requests and remote user onboarding
Configuration Requirements
Before you use Helpdesk Support, confirm the following requirements.
Feature Flag
The HYPR deployment team must enable HYPR Affirm Helpdesk on your tenant. Contact your HYPR representative to confirm enablement. The canonical flag identifier is in the Feature Flags Reference.
Integration Requirements
To use Helpdesk Support, organizations should have the following:
- At least one Identity Provider (IdP) integration configured (Okta, Entra ID, etc.)
- Correct user attribute mapping for verification flows
- Network access for helpdesk agents to reach the HYPR platform
For step-by-step instructions on configuring your identity provider for the Helpdesk portal, see Entra ID: OIDC Integration for HYPR Affirm Helpdesk or Okta: OIDC Integration for HYPR Affirm Helpdesk.
User Management
Helpdesk agents need permissions and access to the following:
- The dedicated Helpdesk portal
- Verification flow management capabilities
- Audit and activity log review functions
A user who authenticates through your Identity Provider but whose token carries no Affirm Helpdesk role, or a role other than Helpdesk viewer or editor, is denied access to the Helpdesk portal. The user sees an Access Not Allowed page. There is no default role. Grant access by placing the user in the group that carries the role they need, and remove access by taking them out of it. For the group and claim setup, see Entra ID: OIDC Integration for HYPR Affirm Helpdesk or Okta: OIDC Integration for HYPR Affirm Helpdesk.
How It Works
Helpdesk Portal Access
The Helpdesk Settings and Helpdesk Users tabs in the HYPR Affirm menu in Control Center display a blue Helpdesk Link banner with a URL and a Copy control. Administrators and analysts can copy this link and share it with Helpdesk agents.
Support agents sign in to the dedicated Helpdesk portal through their organization's existing authentication methods, such as SSO or an enterprise identity provider. Access to the Affirm Helpdesk interface is role-based.
Verification Flow Management
Depending on the Helpdesk role assigned to the user, the Helpdesk app provides either read-focused access or additional operational capabilities.
Helpdesk viewers can review the configured verification workflows and inspect workflow status and links, but they cannot initialize workflows (the Initialize control is not shown).
Helpdesk editors can also initialize workflows by clicking the Initialize link next to the workflow in the Verification Flows view.
The Verification Flows view lists the workflows available in the Helpdesk app, with their current status. The list can include the following:
- Workflow identifier
- Workflow name
- Status, such as Active or Inactive
- Workflow type
- Workflow URL
Helpdesk users can review the available workflows and, depending on role and configuration, use those workflows to begin a verification session.
For Helpdesk editors, the workflow list includes an Initialize link for each workflow row.
Workflow Activity and Details
The Helpdesk app also provides an activity view for individual workflow instances. Use it to review recent verification attempts and inspect their outcome.
The activity list includes fields such as the following. Exact columns and filters can vary by deployment and release.
- Status
- Requester
- Date
- Type
- Workflow ID
- Code
- Decision
- Source
- Initiated By
- Options, with a Details link for opening the corresponding workflow instance
Select a workflow instance to open a detail view for that transaction. The fields shown depend on the workflow design and the verification steps enabled in that flow. The detail page can include the final decision and step-related values captured during the verification.
The detail view can show fields such as the following:
- Date
- Workflow Type
- OTP Send Time
- Phone Number Verified
- IP Location
- Browser Location
- Verification-step results and related values
Workflow Initialization
Where the assigned Helpdesk role allows workflow initialization (the Helpdesk editor role), a Helpdesk user initializes a workflow as follows:
- Click Initialize for the workflow.
- Complete the available requester fields.
- Choose whether to send the workflow link by email, SMS or both.
- Click Initialize.
After the workflow is initialized, the workflow link becomes available to copy.
The initialization dialog includes fields such as the following:
- Login Identifier (email or username)
- Email, plus a Send link via EMAIL option
- Phone number, plus a Send link via SMS option
For the viewer role, the workflow list shows no Initialize link.
For more information about how verification flows work in Affirm, see What the Requester Sees and What the Approver Sees.
Helpdesk Settings
Control Center administrators configure Helpdesk behavior from the Helpdesk Settings tab in the HYPR Affirm menu.
At the top of the page, the Universal Configuration section provides settings that apply across the Helpdesk experience:
- RP App Assignment: Selects the RP application used to determine which users can authenticate into the Helpdesk portal.
- Helpdesk Activity Record Time Window (Hours): Controls how many hours of activity records are shown in the Helpdesk tab.
- Helpdesk Activity Log Table - Available Page Sizes: Defines the selectable page sizes for the Helpdesk activity log table.
Under the universal settings, the page lists all verification flows. Expand a flow to configure Helpdesk behavior for that specific workflow.
Per-workflow settings include the following:
- Workflow Initialization - Redirect URL
- Query String Parameters
- Workflow Initialization - Applicable Properties
- Default Medium Selection
- Visibility In Helpdesk Portal
Managing Helpdesk Users
Control Center administrators manage who can act as a Helpdesk agent from the Helpdesk Users tab in the HYPR Affirm menu.
The tab lists all registered Helpdesk users and their assigned roles. Administrators can add new users, update roles or remove existing Helpdesk users from this list.
To add a new Helpdesk user:
-
In Control Center, go to HYPR Affirm > Helpdesk Users.
-
Click Add User to open the Add User to Affirm Helpdesk dialog.
-
Enter the user's First Name, Last Name and Email Address. The email address is also the username unless you clear Use the email address as the user's username and enter a Username.
-
From the Role drop-down, select Affirm Helpdesk Viewer or Affirm Helpdesk Editor.
-
Click Add to send the invitation.
The invited user receives an email with an enrollment link. The link opens a Device Manager page where the user can enroll a device for access with the HYPR Mobile App or a passkey.
After enrollment, the user can access the Helpdesk portal with the Helpdesk Link you copied from the Helpdesk Settings or Helpdesk Users tab.
Verification Code Validation
Helpdesk agents can search for and validate the verification codes shown to users at the end of their workflow. The code identifies a specific transaction without requiring additional personal details.
Multi-Channel Delivery
Agents can launch new identity verification workflows by sending the URLs to users by email or SMS, or by sharing them through internal communication tools.
Use Cases
HYPR Affirm Helpdesk Support covers the following enterprise support scenarios, where secure identity verification is critical:
- Password Reset Assistance: Verify identity for users who have forgotten passwords, so only legitimate users regain account access
- Access Escalation: Verify identity before granting elevated permissions or access to sensitive systems (temporary or permanent)
- Remote Onboarding: Establish credentials securely for new employees or contractors working remotely
- Account Recovery: Help users regain access through verified identity processes when they've lost authentication methods
- Support Ticket Verification: Verify requester identity before providing assistance or sharing confidential information for sensitive support requests
Security and Compliance
Audit Trail
The verification steps of Helpdesk-initiated workflows are logged in the HYPR Audit Trail, like those of any other workflow. The activity log also shows the source of each workflow and who initiated it.
Data Protection
For how HYPR handles verification data, see the HYPR Privacy Policy and the HYPR Trust Center FAQ.
Access Controls
Helpdesk agents are subject to the same authentication and authorization controls as other HYPR users, so only authorized personnel can initiate verification workflows.
Best Practices
Apply the following practices when you roll out Helpdesk Support.
Workflow Design
When you design Helpdesk workflows:
- Design verification workflows appropriate for the sensitivity of each help desk scenario
- Consider the urgency and sensitivity of different support scenarios
- Test workflows thoroughly before deploying to production
Agent Training
When you prepare agents:
- Train Helpdesk agents on proper verification procedures
- Establish clear escalation paths for complex verification scenarios
- Provide ongoing support and guidance for agents
Monitoring and Review
When you monitor Helpdesk activity:
- Regularly review Helpdesk verification activities
- Monitor for unusual patterns or potential security issues
- Use audit logs to improve processes and identify training opportunities