Skip to main content
Version: 11.3.0

Step Configuration

Each HYPR Affirm verification step has its own configuration page. A step page covers what the step does, its prerequisites, its settings and defaults, what the requester sees, the data collected, and its results, retries and failure outcomes. For retry and failure-outcome behavior shared by all steps, see Injectable Outcomes and Retry Limits.

For the flow editor view, including which steps are available, how they are grouped and how to save or revert changes, see Configure Verification Steps.

Steps and the Data They Collect​

The following table lists every step a verification flow can include, in the order the requester meets them. The order is fixed; the flow editor turns steps on and off but does not reorder them. Custom steps run after the step you choose for them.

StepPurposeData Collected from the Requester
InstructionsLists the steps in the flow before it starts; always shownNone
ConsentPresents the consent notice, which the requester must accept to continue; always shown. See Consent ScreenThe requester's acceptance
Login IdentifierIdentifies the requester and looks up their directory record; always requiredThe username or email the requester types
Phone Number / Email VerificationConfirms that the requester controls the phone number or email address on file, optionally with a one-time codeThe phone number the requester types, the chosen channel and the code the requester enters
LocationChecks the requester's location against the address on file and the location policyThe browser location, if the requester allows it, and the IP address of the connection
Identity Verification via Verified CredentialsVerifies an Entra Verified ID credential presented from Microsoft AuthenticatorThe Verified ID credential the requester presents
Document and Biometric VerificationVerifies a government-issued ID and, with Liveness Check, compares it with a live selfie, with optional Motion Detection, Dual Document and compliance checksImages of one or two identity documents and, with Liveness Check, a selfie or video capture; a date of birth and address when Identity Verification With Document Issuer needs them and the directory lacks them
KYC Compliance Checks (AML / OFAC / Watchlists)Options of Document and Biometric Verification that screen the requester against watchlists or check the document with its issuerNo capture of its own; uses the Document and Biometric Verification data
Photo ID and Liveness CaptureCompares a live selfie with a photo ID the requester captures or uploadsA photo of an ID and a selfie capture
Liveness-Only (Anchor Image)Compares a live selfie with an anchor image from your directory, supplied by a User Image Directory Source customizationA selfie capture; see the step page for the document-upload fallback
Custom Verification StepRuns your organization's own verification page, registered through the Code Customization APIWhatever your custom step collects
Approver Chat and VideoPlaces the requester in a live chat, with optional video, with the assigned approverChat messages and, if either party turns it on, live camera and microphone streams
Escalate to Live ChatSends a requester whose step failed to a live chat with an escalation approver at the end of the flowAs for Approver Chat and Video
AttestationRequires an approver to approve or decline the requester's results before an outcome is issuedNone from the requester; the approver's decision and notes
Verified OutcomeDefines what the requester receives after a successful verificationNone
Unverified OutcomeDefines what the requester sees after a failed or denied verificationNone

For how Affirm handles document and biometric data, see Biometric Data and the Privacy Notice.

Profile Data Each Step Requires​

Most verification steps compare what the requester presents against the profile held in your system of record. Use this table when you plan a flow, and again when you write a User Directory customization that has to supply the data.

StepProfile Data It Requires
Login IdentifierThe login identifier itself must resolve to a record in the system of record.
Phone Number / Email VerificationA mobile phone number or an email address.
LocationThe full postal address.
Document and Biometric VerificationFirst name and last name. Identity Verification With Document Issuer also uses a date of birth and an address, and asks the requester for them when the record lacks them.
Photo ID and Liveness CaptureNone, unless the flow has a Custom Directory Source; the step then reads the requester's anchor image (see Liveness-Only). Otherwise it compares the captured selfie against the captured document.
Liveness-Only (Anchor Image)An anchor image, supplied by a User Image Directory Source customization.
Approver Chat and VideoA manager identifier, unless an approver is configured explicitly on the flow.
Escalate to Live ChatA manager identifier, unless an approver is configured explicitly on the flow.
AttestationA manager identifier, unless an approver is configured explicitly on the flow. HYPR automated approval cannot be used with this step.
Verified OutcomeNone.
Unverified OutcomeNone.
Match the data you have

Choose steps whose required data your system of record holds. Each step you add raises the level of assurance and adds a step for the requester to complete. Select the set that meets your requirement rather than the largest set available.