Configuring Verification Steps
Verification Steps
The Verification Steps section of the HYPR Affirm workflow editor lists every step available for the workflow. Use the left sidebar to jump to it or to any step's card. A step's settings appear on its card while the step is on.
Each step card that can be turned off shows a switch in the upper right, labeled Deselect Step while the step is on and Select Step while it is off. The Instructions, Consent and Login Identifier cards are marked Required and have no switch, and the Verified Outcome and Unverified Outcome cards are always part of the flow. A flow needs at least one verification step besides Login Identifier.
Steps always run in a fixed order: Instructions, Consent, Login Identifier, Phone Number / Email Verification, Location, Verified Credential, Document and Biometric Verification, Photo ID and Liveness Capture, Approver Chat and Video, then the outcome. A live chat added by Escalate to Live Chat runs before the outcome. Custom steps run after the step you choose for them.
This page lists the steps by category. For configuration details on a specific step, follow the link in the table.
Instructions and Consent
Two screens open every flow. Both are required and have no settings in the step card. You set their text in Affirm Studio and the consent notice in Consent Screen.
| Step | What it does |
|---|---|
| Instructions | Lists the steps the requester completes, as a numbered list such as "Verify your phone number" and "Verify your location". |
| Consent | Presents the consent notice, which the requester accepts with Accept before continuing. |
Identity Capture
These steps collect the core identity evidence.
| Step | What it does |
|---|---|
| Login Identifier | Always required. Captures the requester's work login identifier so the rest of the flow can resolve their profile. |
| Phone Number / Email Verification | Checks the phone number the requester types against the number on file and, optionally, sends an OTP to the requester's phone or email to confirm access to that channel. On in a new flow. |
| Document and Biometric Verification | Verifies an uploaded photo ID and, with Liveness Check, compares it with a live selfie. Optional Motion Detection, Dual Document, AML/OFAC and Identity Verification with Document Issuer. |
| Photo ID and Liveness Capture | A lighter alternative to Document and Biometric Verification that compares a photo ID with a selfie, without compliance overlays. |
| Verified Credential | The requester presents an Entra Verified ID credential stored in Microsoft Authenticator. |
| Liveness-Only (Anchor Image) | Not a separate card. When the flow has a Custom Directory Source, Photo ID and Liveness Capture compares the live selfie with the requester's directory photo, the anchor image. When a usable anchor image is found, no photo ID upload is required. |
Policy and Context
These steps gather context, such as location and network, or apply compliance and risk-policy logic on top of identity capture.
| Step | What it does |
|---|---|
| Location | Collects the browser location and IP address and evaluates them against the address on file, Known Locations, IP allow/block lists, distance threshold and country block list. For the policy-composition perspective, see Network and Location Policy. |
| KYC Compliance Checks | Optional compliance screening (AML, OFAC and watchlists) attached to Document and Biometric Verification. |
Custom
Custom steps are pluggable steps that extend the platform with organization-specific verification logic. They have no card in the flow editor; you configure them through the Code Customization API.
| Step | What it does |
|---|---|
| Custom Verification Step | Adds a custom single-page application (SPA), registered through the Code Customization API, as a verification step. Useful for proprietary knowledge-based authentication (KBA), partner verification or in-house fraud-detection integration. |
Approval and Attestation
These are the human-review steps and the live-chat escalation path. When Approver Chat and Video or Attestation is on, the flow needs a human approver; when both are off, HYPR (automated approval) decides.
| Step | What it does |
|---|---|
| Approver Chat and Video | Live chat and video session between the requester and the assigned approver. Off in a new flow. |
| Escalate to Live Chat | Sends a requester whose step failed into a chat session with the escalation approver at the end of the flow. Cannot be combined with Approver Chat and Video. |
| Attestation | Human-approver attestation before the outcome fires. Off in a new flow. |
Outcomes
These terminal steps define what happens at the end of the flow. Both are always part of the flow.
| Step | What it does |
|---|---|
| Verified Outcome | What happens after a successful verification: Device Manager handoff, Entra TAP, Verified ID, Okta password reset, custom redirect or in-flow result display. |
| Unverified Outcome | What happens when verification fails or is denied: custom redirect or in-flow denial display. |
Save and Revert
After configuring step-level options in the workflow editor, click Save at the top right to apply changes, or click Revert Changes to discard unsaved edits. Delete removes the workflow entirely, after you confirm with Delete Verification Flow.
Related
- Create and Manage Verification Flows: workflow creation, applications, retry limits
- Approvers and Escalation Approvers: approver chain configuration
- Injectable Outcomes & Retry Limits: per-step retry and failure-outcome configuration
- Step Configuration: configuration pages for every step type, including the data each step collects