Skip to main content
Version: 11.3.0

Configuring Verification Steps

Verification Steps​

The Verification Steps section of the HYPR Affirm workflow editor lists every step available for the workflow. Use the left sidebar to jump to it or to any step's card. A step's settings appear on its card while the step is on.

Each step card that can be turned off shows a switch in the upper right, labeled Deselect Step while the step is on and Select Step while it is off. The Instructions, Consent and Login Identifier cards are marked Required and have no switch, and the Verified Outcome and Unverified Outcome cards are always part of the flow. A flow needs at least one verification step besides Login Identifier.

Steps always run in a fixed order: Instructions, Consent, Login Identifier, Phone Number / Email Verification, Location, Verified Credential, Document and Biometric Verification, Photo ID and Liveness Capture, Approver Chat and Video, then the outcome. A live chat added by Escalate to Live Chat runs before the outcome. Custom steps run after the step you choose for them.

This page lists the steps by category. For configuration details on a specific step, follow the link in the table.

Two screens open every flow. Both are required and have no settings in the step card. You set their text in Affirm Studio and the consent notice in Consent Screen.

StepWhat it does
InstructionsLists the steps the requester completes, as a numbered list such as "Verify your phone number" and "Verify your location".
ConsentPresents the consent notice, which the requester accepts with Accept before continuing.

Identity Capture​

These steps collect the core identity evidence.

StepWhat it does
Login IdentifierAlways required. Captures the requester's work login identifier so the rest of the flow can resolve their profile.
Phone Number / Email VerificationChecks the phone number the requester types against the number on file and, optionally, sends an OTP to the requester's phone or email to confirm access to that channel. On in a new flow.
Document and Biometric VerificationVerifies an uploaded photo ID and, with Liveness Check, compares it with a live selfie. Optional Motion Detection, Dual Document, AML/OFAC and Identity Verification with Document Issuer.
Photo ID and Liveness CaptureA lighter alternative to Document and Biometric Verification that compares a photo ID with a selfie, without compliance overlays.
Verified CredentialThe requester presents an Entra Verified ID credential stored in Microsoft Authenticator.
Liveness-Only (Anchor Image)Not a separate card. When the flow has a Custom Directory Source, Photo ID and Liveness Capture compares the live selfie with the requester's directory photo, the anchor image. When a usable anchor image is found, no photo ID upload is required.

Policy and Context​

These steps gather context, such as location and network, or apply compliance and risk-policy logic on top of identity capture.

StepWhat it does
LocationCollects the browser location and IP address and evaluates them against the address on file, Known Locations, IP allow/block lists, distance threshold and country block list. For the policy-composition perspective, see Network and Location Policy.
KYC Compliance ChecksOptional compliance screening (AML, OFAC and watchlists) attached to Document and Biometric Verification.

Custom​

Custom steps are pluggable steps that extend the platform with organization-specific verification logic. They have no card in the flow editor; you configure them through the Code Customization API.

StepWhat it does
Custom Verification StepAdds a custom single-page application (SPA), registered through the Code Customization API, as a verification step. Useful for proprietary knowledge-based authentication (KBA), partner verification or in-house fraud-detection integration.

Approval and Attestation​

These are the human-review steps and the live-chat escalation path. When Approver Chat and Video or Attestation is on, the flow needs a human approver; when both are off, HYPR (automated approval) decides.

StepWhat it does
Approver Chat and VideoLive chat and video session between the requester and the assigned approver. Off in a new flow.
Escalate to Live ChatSends a requester whose step failed into a chat session with the escalation approver at the end of the flow. Cannot be combined with Approver Chat and Video.
AttestationHuman-approver attestation before the outcome fires. Off in a new flow.

Outcomes​

These terminal steps define what happens at the end of the flow. Both are always part of the flow.

StepWhat it does
Verified OutcomeWhat happens after a successful verification: Device Manager handoff, Entra TAP, Verified ID, Okta password reset, custom redirect or in-flow result display.
Unverified OutcomeWhat happens when verification fails or is denied: custom redirect or in-flow denial display.

Save and Revert​

After configuring step-level options in the workflow editor, click Save at the top right to apply changes, or click Revert Changes to discard unsaved edits. Delete removes the workflow entirely, after you confirm with Delete Verification Flow.