Policy and Enforcement
Policy in HYPR Affirm describes the rules that evaluate where a verification can take place and how the flow responds to risk signals. Policy sits on top of the verification steps in a workflow and does not change which steps the workflow contains.
This section explains the policy concepts. To configure the steps that carry policy (Location, Escalation), see Step Configuration.
Policy Composition
A workflow can combine several policy controls. Each control is evaluated independently and contributes to the per-step or per-flow outcome:
- Location policy: Known Locations (one for each headquarters or office), IP allow and block lists, distance threshold and country block list. Evaluated as part of the Location step.
- Risk-signal escalation policy: Ordered Pass or Fail rules for each verification action, evaluated against that action's risk signals. A Fail rule's failure action can deny, escalate, redirect or continue. Built-in default rules apply until you assign a Policy Evaluation Kit to the workflow.
Evaluation Order
Within the Location step, every configured check runs, and the step passes only when all of them pass: the country block list, the IP block and allow lists, and the distance threshold. Affirm records the first failure in a fixed order; see Order of Precedence.
Known locations are not a separate check. Their addresses count as expected locations for the distance check, and their IP addresses join the allow list when it is enabled.
For detailed configuration of each control, see the following pages:
- Network and Location Policy — full reference for the Location-step policy controls, including multiple headquarters
- Affirm Risk Policy Builder — Control Center UI for building Policy Evaluation Kits (rules, predicates, signals and actions)
- Risk-Signal Escalation Policy — the policy model and how policy decisions surface in observability
How Policy Interacts With Steps
Policy and verification steps interact as follows:
- Policy controls fire within a verification step (Location runs its IP, distance and block checks before producing the step outcome)
- Risk-signal policy is evaluated for each verification action: the rules for that action read the action's risk signals and return Pass or Fail. A Fail rule lets the requester retry while the retry budget allows, then applies its failure action, which can escalate the verification.
- When your tenant uses the Affirm Risk Policy Builder, the Policy Evaluation Kit assigned to the workflow sets the retry budget and the failure action for each action it covers, and the step's Retry Limit and Failure Outcome settings don't apply. Otherwise the step's settings decide what happens when a step fails: deny, redirect or continue, optionally with escalation to live chat. See Injectable Outcomes & Retry Limits.
Related
- Affirm Risk Policy Builder — admin UI for building Policy Evaluation Kits
- Risk-Signal Escalation Policy — policy model and observability
- Network and Location Policy — Location policy deep-dive
- Location step — step-config-focused view of the same controls
- Escalation (concept) — two-mechanism overview (approver chain + risk signal)