Creating and Managing Verification Flows
Verification Flows
HYPR Affirm verification flows define what happens when a requester is asked to prove their identity: the sequence of verification steps, which applications the flow applies to and how outcomes are handled. This page covers creating a workflow, managing existing workflows, assigning applications, configuring workflow-level retry limits and assigning advanced customizations.
Creating a Workflow
-
At the top right, click + Verification Flow. The New Verification Flow dialog opens.
-
Enter a Name of up to 30 characters and, optionally, a Description of up to 255 characters.
-
Select a workflow Type.
- Onboarding: employee onboarding
- Recovery Flow: account recovery, for example for an employee who has a new device
- CC Admin: verification of administrators' access to Control Center
- Only one CC Admin workflow can exist at a time
- CC Admin must use Redirect to Device Manager to register a new login method as an outcome
- New members of CC Admins must complete an Affirm flow when Affirm is enabled
- Custom: flows that do not fit the three standard types, with a free choice of outcome and assigned application
-
Click + Verification Flow to save. Control Center opens the new flow in the flow editor, and the flow is listed on the Affirm Verification Flows tab.
A new flow starts with the Login Identifier and Phone Number / Email Verification steps, the Display verification result to the end user outcomes (or the Device Manager outcome for CC Admin) and HYPR (automated approval) as its approver. It starts Inactive; turn it on with the Active switch in the flow editor when it is ready.
Managing Workflows
The Verification Flows tab lists every workflow configured for the tenant. From this tab, you open individual flows, copy the flow URL for requesters and see whether each flow is active or inactive.
The following table describes the columns in the list.
| Field | Description |
|---|---|
| Name | The name of the workflow. |
| Type | The type of workflow. [ Onboarding | Recovery Flow | CC Admin | Custom ] If CC Admin is chosen, the only acceptable Outcome is Redirect to Device Manager to register a new login method. |
| URL | The link to give to requesters, for example <tenant_URL>/ui/idv/?verificationFlowId=<verificationFlowId>.Use the copy icon to copy this URL for distribution. |
| Description | The description entered when the workflow was created. |
| Status | A label indicating the current status. [ ACTIVE | INACTIVE ] |
| RpApp | The HYPR Relying Party Application associated with this workflow, for example the RP App associated with the integration being used. Only one RP Application can be associated with a workflow. |
To manage a workflow's configuration, click the row where it is listed. The workflow editor opens with the General tab in view and a left sidebar listing every configurable section.
The General tab shows the workflow's unique identifier, the URL used by requesters, the creation and last-updated timestamps and the editable fields: Name, Type, Application, Description, Workflow Retry Limit and Block Duration. The Active / Inactive switch at the top turns the flow on and off. A requester who opens an inactive flow sees Invalid configuration with "The Affirm workflow has not been enabled for your account."
Use the top-right buttons to Save the workflow, Revert Changes to discard unsaved edits or Delete the workflow.
The left sidebar groups the workflow's configuration into three collapsible sections, General, Verification Steps and Approvers, plus the Advanced Customization group at the bottom. Click any item to scroll directly to that section in the editor.
Applications
On the General tab, the Application field assigns this workflow to a specific HYPR Relying Party Application. Choose one of the applications available on the tenant from the list.
Select No Application to leave the workflow unassigned, for example for testing or for flows invoked only through the API.
Workflow Retry Limits
Set an overall attempt limit and block duration for the workflow to prevent abuse and protect against repeated failed verification attempts. The editor describes them as follows: "Workflow Retry Limit" sets the maximum number of times a requester can attempt verification workflows associated with this configuration. Any further attempts will be blocked for the requester for the duration set by "Block Duration".
-
Workflow Retry Limit: Set the maximum number of verification attempts a requester can make within a specified time window. Enter 0 to 10 attempts (default 10) and select the time window from the dropdown: 0 minutes (default), 30, 60 or 90 minutes, or 2, 3, 4, 6, 12, 18 or 24 hours. With a window of 0 minutes, the limit is not applied.
-
Block Duration: Configure how long requesters are blocked from attempting verification after exceeding the retry limit. Select the duration from the same options, from 0 minutes (default) to 24 hours.
A requester who reaches the limit within the window is blocked for the block duration. For how Affirm counts attempts, what a blocked requester sees and how to lift a block, see Workflow Retry Limit and Block Duration. For per-step retry limits and step-level outcomes, see Injectable Outcomes & Retry Limits.
Advanced Customization
The Advanced Customization section at the bottom of the workflow editor lets you assign customizations that override default Affirm behavior for this specific workflow. You define the customizations themselves in Affirm Customizations (Code Customization API); in the workflow editor, you choose which existing customization applies.
The panel groups the assignment slots into the following areas:
OIDC Settings and User Directory
- Approver OIDC Setting: overrides the OIDC client used for approver invitations
- Custom User Directory, Custom Phone Directory, Custom Email Directory, Custom DOB Directory: fetch the corresponding requester attribute from a custom source instead of the default integration
Image Directory (Anchor Image and Writeback)
- Custom Directory Source: fetches the requester's reference image, the anchor image, from an external directory. It is used with the Photo ID and Liveness Capture step: when a usable anchor image is found, the step compares the selfie with it and skips the photo ID upload. See Liveness-Only (Anchor Image)
- Custom Writeback Directory: sends captured verification images to an external directory after the verification is approved, by an approver or by HYPR (automated approval) (used by the Document and Biometric Verification and Photo ID and Liveness Capture steps)
- Writeback Rotation Interval: the minimum time before the same user's images are written back again; set to
0to write back after every verification
For full Directory Image Writeback details, see Directory Image Writeback.
Email, SMS and Outcome
- Custom Email Sender: sends Affirm emails through a custom SMTP service instead of HYPR's default
- SMS Send Customization and SMS Verify Customization: send and verify SMS through a custom transport
- Outcome API Call: runs a custom API call before the configured outcome fires
Data Retention Policy
- Document & Biometric: how long document and biometric verification data is stored after a session completes, 1 day or 7 days (default). The setting applies when the flow includes the Document and Biometric Verification step; see Document and Biometric Verification.
Content and Risk Policy
- Content Customization Kit: applies a per-screen content customization to this workflow (see Affirm Studio)
- Policy Evaluation Kit: applies a kit built in the Affirm Risk Policy Builder that drives per-action Pass/Fail decisions based on risk signals
Related
- Injectable Outcomes & Retry Limits: per-step retry and outcome configuration
- Configure Verification Steps: per-step configuration and outcomes
- Approvers and Escalation Approvers: approver assignment, chains and escalation
- Advanced Setup: integration prerequisites and IdP attribute requirements
- Activity Log: review verification attempts and decisions