Skip to main content
Version: 11.3.0

Identity Verification and Assurance Strategies Playbook

Considerations for an Affirm Deployment

This playbook helps you plan and deploy HYPR Affirm verification flows for enterprise use cases such as onboarding, help desk and account recovery.

Introduction​

HYPR Affirm is an automated identity verification solution. It confirms that employees are who they claim to be at the moments that matter most: when an employee sets up their first sign-in during onboarding, when an employee recovers access to an account and when a caller asks the help desk for help.

An employee receives a link to a verification flow, opens it in a web browser on a phone or a computer, and completes the checks your flow includes. Affirm records the result as one auditable decision and then carries out the outcome you configure, such as sending the employee on to register a passwordless sign-in method. For the screens an employee sees, see What Employees Experience.

Affirm checks identity with one-time codes, location, government-issued documents, live selfies, Microsoft Entra Verified ID credentials, compliance screening and approver review. For each verification step and what it checks, see Verification Steps.

Benefits of using HYPR Affirm:

  • Fraud prevention: Identify impersonation attempts before granting access or resetting credentials.
  • Automated screening: Reduce manual review with automated document, biometric and compliance checks.
  • One configurable flow: Combine document, biometric, location, one-time code and approver checks in a single verification flow.
  • Monitoring: Track verification results across all flows in the Activity Log.
  • Retention controls: Set how long document and biometric verification data is retained per workflow (7 days by default, or 1 day) to match your organization's data policies. See Data Retention. For HYPR's certifications, audit reports and privacy commitments, see the HYPR Trust Center.
  • Integration flexibility: Hand a verified employee off to an identity provider, for example to receive a Microsoft Entra ID Temporary Access Pass (TAP).

What You Will Have at the End of This Playbook​

After completing this playbook, you will have:

  • Defined specific use cases where Affirm solves your identity verification business needs

  • Established the source of truth for the identity verification user data, such as an identity provider like Okta or Entra ID that sources the user data from your records system. This may require coordination with other departments within your organization

  • Created one or more Affirm verification workflows that implement the business logic

  • Outlined a schedule to roll out Affirm to your organization, including the employee communications that announce it

Planning for a HYPR Affirm Deployment​

Start by defining the business challenges you want identity verification to address. The following section provides a template for recording business requirements and the questions to resolve before implementation.

Requirements Analysis​

Requirement Example​

Statement: Streamline the user-provisioning process for first-time user verification

Interpretation: The current business process involves human inspection of a scanned verification document (passport, driver’s license, etc.), which is a prerequisite for creating user accounts in the IT system. The business would like to automate verification to improve security and accuracy of first-time user provisioning. In addition, the user should be able to immediately register to create their primary authentication account.

QuestionAnswer
What ID would you like users to enter on the “Let’s get started” screen? This can be a username, an email address or another value such as an employee ID. The value provided is used to look up the user profile in the system of record.
Document verification requires Affirm to retrieve First Name and Last Name from a system of record to compare with the names on the ID. What system do you want to retrieve that data from?
How would you like to integrate identity verification into your existing onboarding process?
How will users be notified to start the verification flow?
Do you have any branding or content customization requirements?
Which HYPR web application do you want to use for the initial HYPR registration after successful verification?

General Approach for Affirm Verification Flows​

Regardless of the business use case, make the following decisions to configure an Affirm verification flow:

  1. Determine what ID you want users to enter on the “Let’s get started” screen. This can be a username, an email address or another value such as an employee ID. The value provided is used to look up the user profile in the system of record.

  2. Decide which verification steps are needed to meet the business requirements. More steps increase the level of assurance, but also add friction and increase the burden on the user.

    • For higher‑risk flows, consider enabling Document and Biometric Verification with Document Type Restriction so that only a limited set of high‑security government‑issued documents from allowed issuing countries can be presented to the user.
  3. Each verification step requires some information from the user profile from the system of record. For example, document verification requires first name and last name. For each of your verification steps, review the documentation to confirm what data is required, and check whether that data is available in your system of record.

  4. If you are not using the HYPR Okta or Entra ID integrations, write a custom JavaScript program to query your system of record for the user profile information. See Customizations in the product documentation for more information.

  5. Determine what the outcome of the verification flow should be in the case of both successful verification and unsuccessful verification. If none of the default outcomes matches your use case, write an Outcome customization.

  6. If you want to change the text or use your own branding, review the HYPR features Configuring End User Screen Management and Affirm Studio, and plan the design accordingly.

HYPR Affirm Overview​

HYPR Affirm uses a workflow model for identity verification. Users receive a URL and are guided through a series of steps (screens) that ask them to present identifying information. As an administrator, you configure Affirm by creating a workflow and choosing which verification steps it includes. When the workflow is created, Affirm generates a URL to give to the end user.

Verification Steps​

Affirm offers a configurable set of verification steps; each step requires specific user-profile fields from the system of record (SoR) as a basis for comparison. Every flow starts with the Instructions and Consent screens. The available steps are:

  • Login Identifier (required): the entry point for the flow, where the employee enters the identifier Affirm uses to look up their profile. See Login Identifier.
  • Phone Number / Email Verification: the employee enters a one-time code sent by text message or email. See Phone Number / Email Verification.
  • Location: compares the employee's browser or network (IP) location against rules you set, such as allowed and blocked IP addresses, blocked countries and known office locations, and shows the location to the approver. See Location.
  • Verified Credential: the employee presents a Microsoft Entra Verified ID credential from Microsoft Authenticator. See Verified Credentials.
  • Document and Biometric Verification: checks a government-issued ID, such as a passport or driver's license, for signs of forgery or tampering and, with the optional liveness check, compares a live selfie with the photo on the ID. Document Type Restriction limits which documents the employee can present. Optional compliance screening (AML and OFAC checks) runs with this step; see KYC Compliance Checks. See Document and Biometric Verification.
  • Photo ID and Liveness Capture: compares a live face capture with a photo ID the employee provides or, for known employees, with an anchor image from your directory (for Liveness-Only / Anchor Image flows). See Photo ID and Liveness Capture.
  • Approver Chat and Video: the employee and an approver, such as their manager, meet in a live chat or video call. See Approver Chat and Video.
  • Attestation: an approver, such as the employee's manager, reviews the results and attests to the employee's identity. This human review gates the outcome. See Attestation.
  • Verified Outcome / Unverified Outcome: terminal steps that fire actions on success or failure. See Verified Outcome and Unverified Outcome.

A step's failure outcome can also escalate the requester to a live chat with an approver; see Escalate to Live Chat.

For the data each step collects and the profile data each step requires, see Step Configuration. For the configuration walkthrough, see Create a Verification Flow.

Verification Flow Types​

When you create a verification flow, you choose its type based on the business use case:

  • Onboarding: for first-time user provisioning
  • Recovery Flow: for credential recovery
  • CC Admin: for provisioning HYPR Control Center admin accounts. Only one CC Admin flow can exist per tenant

Application Assignment​

Application assignment associates an Affirm verification flow with an identity provider (IdP) integration previously configured in HYPR Authenticate. IdP integrations allow HYPR to be used as a passwordless authentication mechanism to the IdP. Each IdP integration has an associated application name, also called the relying party application (or rpAppId). Affirm uses the existing IdP application to retrieve user profile data needed as a baseline for the identity verification. If you do not already have an IdP integration with HYPR, you can create one just for this purpose (either Entra or Okta).

If you do not have an IdP or want to use a different source, you can use the Advanced Customization to write the JavaScript to retrieve user profile data from your system of record.

You need an IdP integration in the following scenarios:

  • The selected Verified Outcome is Redirect to Device Manager to register a new login method

  • You are not using an Advanced Customization to retrieve identity data from an external data source

If either scenario applies, select the application when you configure the Affirm workflow.

See HYPR Integrations for more information on creating an integration.

Advanced Settings​

HYPR Affirm has two types of advanced settings:

  • Customizations: custom code that runs during a workflow
  • OIDC Settings: sets up Affirm as an OIDC relying party

These advanced settings provide flexibility for business scenarios that do not fit into the out-of-the-box Affirm workflows.

Customizations​

HYPR Affirm allows multiple types of customizations that override the default behavior in key parts of the verification flow. For example, if you need to pull user profile data from an external system rather than an IdP integration, you write JavaScript code to retrieve that data as part of the identity verification (IDV) flow.

The following table lists the customization types.

Customization TypeDescription
User Directory SourceSpecifies the user-profile source for the requester.
User Phone Number Directory Source / User Email Directory Source / User Extended Info Directory SourcePer-attribute directory sources for specific user-profile fields when those attributes live in different systems from the primary user profile.
User Image Directory SourceProvides an anchor image to the Photo ID and Liveness step (used for Liveness-Only / anchor-image verification flows).
User Image Writeback DirectoryPushes verification images (selfies, document captures) to an external directory after a successful verification. See Directory Image Writeback.
SMS SendingSends SMS through a custom REST call instead of HYPR's SMS service.
SMS VerifyingHandles the result of a verified SMS code through a custom REST call instead of HYPR's SMS service.
Email SendingSends emails through a custom REST call instead of HYPR's SMTP servers.
Outcome API CallExecutes after the verification decision has been made at the end of the flow.
Custom Step Preprocessor / Custom Step Function / Custom Step PostprocessorCode customizations attached to a Custom Verification Step.

For customizing the email templates themselves (branding edits, template revisions, version history and custom image uploads), see Email Notification Customization.

See Customizations for the full type list and the customization-creation walkthrough.

OIDC Settings​

OIDC settings can be used to trigger OIDC authentication for the requester or approver.

In Control Center, assign an OIDC setting for the approver in the verification flow's Advanced Customization > OIDC Settings section (Approver OIDC Setting). OIDC settings can also be assigned through the HYPR Affirm API.

For the requester, the setting forces OIDC authentication at the specified part of the flow. Assign it to the verification flow, and enable the setting on the specific step where the authentication should take place.

For the approver, the setting forces OIDC authentication before the approver enters a verification flow to which they were invited by email or SMS.

Affirm Studio​

Affirm Studio is the screen management interface for HYPR Affirm. It lets administrators design the content and messaging for each verification step by creating reusable kits of screen customizations (titles, descriptions, instructions, button labels and other copy) and applying those kits to one or more verification flows. You can preview changes before they are applied, so that end-user screens follow corporate branding and communication guidelines across the entire workflow. See Configuring End User Screen Management and Affirm Studio for how to tailor the look and feel of your verification workflows.

Affirm API​

HYPR Affirm offers REST APIs to integrate Identity Verification into custom web apps or other integrations. For example, a self-service password reset page could invoke an Affirm verification flow prior to displaying the password reset page, which minimizes phishing attempts. See HYPR API docs for more information.

Solution Deployment Overview​

Use the following checklist to prepare a solution that meets your business requirements:

Solution Deployment Use Cases​

This section describes use cases in which Affirm automates traditionally manual business processes with a high degree of assurance.

First-Time User Provisioning​

Affirm suits first-time user provisioning, where a remote user needs to verify their identity before an account is activated and credentials are issued.

After you create a verification flow with the steps needed to assure proper user identification, the use case works like this:

  1. The user-provisioning system is updated with the new user's data and automatically emails them (to their personal email address if they don't yet have a corporate email) a link to the Affirm verification flow.

  2. The user successfully completes the verification flow.

  3. The designated approver is notified that the user completed and inspects the result of the verification flow.

  4. If appropriate, the approver approves the verification and the provisioning process continues as usual.

First-Time Workstation Provisioning​

A first-time user can verify their identity, register a passkey and unlock a corporate workstation in a single onboarding flow. With the HYPR Passwordless desktop application, HYPR Mobile App with Passkeys and the Microsoft Entra ID integration, this scenario is possible without the user ever needing to know a password.

Configuration​

  1. Configure the Microsoft Entra ID HYPR Enterprise Passkey integration

  2. Deliver the Entra-joined workstation to the user with the HYPR Passwordless client pre-installed

  3. Configure an Affirm verification flow with the Redirect to Device Manager to register a new login method outcome

User Experience​

  1. The user receives their corporate workstation and an email with a link to the Affirm verification flow.

  2. After successful verification, they are presented with a registration screen where they register a passkey using the HYPR Mobile App.

  3. They boot up their workstation and scan a QR code on the login screen, which logs them in to their workstation with HYPR passwordless authentication and a passkey.

  4. They can now access Microsoft with the same passkey and, from the Entra portal, access other corporate applications through SSO.

Helpdesk​

Affirm includes a separate web-based Helpdesk application that lets Helpdesk operators initiate identity verifications on behalf of callers, replacing shared-secret challenges (PINs, "secret" questions) that are prone to social engineering. The end-user walkthrough and admin configuration are in the main docs. See HYPR Affirm Helpdesk Support and, for OIDC-based agent authentication, Okta OIDC Integration for HYPR Affirm Helpdesk or Entra ID OIDC Integration for HYPR Affirm Helpdesk.

Typical Helpdesk Flow​

  1. The user calls the Helpdesk for support; the operator needs to verify the caller's identity.
  2. The operator opens the HYPR Helpdesk Application and clicks Initialize on the appropriate verification flow.
  3. The operator fills in the requester details and sends the link by email, SMS or copy-to-clipboard.
  4. The user completes the verification; on completion they share the displayed verification code with the operator.
  5. The operator locates the matching row in the Helpdesk activity list, using the Code column, and checks the decision (Verified or Unverified).
  6. On Verified, the operator proceeds with the support request. On Unverified, the operator follows the failure-path business process.

Roles​

The Helpdesk application supports two roles:

  • Helpdesk viewer (AFFIRM_HELPDESK_VIEWER): can inspect workflow links, status and results, but cannot initialize a new verification.
  • Helpdesk editor (AFFIRM_HELPDESK_EDITOR): can additionally initialize verifications.

Prerequisites​

The HYPR deployment team enables HYPR Affirm and the Affirm Helpdesk on your tenant before the Helpdesk application becomes available. See the Feature Flags Reference for the capabilities HYPR enables per tenant.

Authentication Method​

The Helpdesk application supports two authentication methods for operators:

  • HYPR passwordless: operator authenticates directly to the Helpdesk RP application with HYPR Passwordless.
  • OIDC via IdP: operator authenticates through an IdP (for example, Okta) that issues an affirm_helpdesk_role claim valued AFFIRM_HELPDESK_VIEWER or AFFIRM_HELPDESK_EDITOR (or the HYPR_-prefixed equivalents).

Both paths require an RP application for the Helpdesk, which you create in Control Center Advanced Mode (RP application creation is available only there). See Adding an RP Application for the canonical procedure. Then assign the new RP in HYPR Affirm → Helpdesk Settings → Universal Configuration, and add operator users in HYPR Affirm → Helpdesk Users. For the OIDC path, Okta OIDC Integration for HYPR Affirm Helpdesk covers the full claim mapping and authorization-server setup.

Accessing the Helpdesk Application​

When HYPR has enabled the Helpdesk and the RP application is assigned, operators reach the Helpdesk at the following URL:

https://<your-tenant>.hypr.com/cc/ui/idv/support/helpdesk

Password Reset​

Some help desk calls involve a user who has lost or forgotten their password. The Affirm Helpdesk application can address this use case, and the scenario can go further by removing the help desk call altogether.

The idea is to replace the “Forgot password?” link with an Affirm verification link.

For Okta, the built-in Okta Password Reset outcome sends a verified requester to an Okta password reset page, with no customization needed. For other directories, use an Outcome customization as described in the following configuration.

Sign-in page with a Forgot password link, which the Affirm verification link replaces

Configuration​

  1. Create an Affirm verification flow with the steps needed to assure proper user identification.

  2. Create an Outcome customization that makes API calls to your user directory or IdP to reset the user password. The Outcome customization is JavaScript code that runs after the verification flow completes.

  3. Display the new password to the user when they successfully verify their identity.

    Approved outcome screen showing a temporary password returned by an Outcome customization

Tips and Tricks​

IDV Failure Modes​

Understand the ways a document check can fail. The document report groups its results into breakdowns such as data comparison, data validation, image integrity, visual authenticity, data consistency and age validation. Each breakdown result is clear, consider or empty when the check did not run. For an example report breakdown, see IDV Failure Modes in Preparing to Deploy HYPR Affirm.

Adding a Custom User Directory Source​

If your user-profile data lives outside Okta or Entra (your records system, a custom directory or an internal API), write a User Directory Source code customization. The customization receives a loginIdentifier, queries your system and returns the user-profile fields Affirm needs (first and last name, email, phone, location attributes and so on).

The full input/output contract and the customization creation walkthrough (HYPR Affirm > Advanced Settings > Code Customizations > New Customization > User Directory Source) are in Affirm Customizations. After you register it, assign it to a verification flow in the workflow's Advanced Customization settings.

For the script itself (the entry point, the design pattern, a worked example, error handling and how to test before attaching it to a flow), see Writing Affirm Code Customizations.

For per-attribute sources (when phone, email or the extended profile details come from different systems than the primary user profile), separate User Phone Number Directory Source, User Email Directory Source and User Extended Info Directory Source customization types are available.

For an anchor-image source (Liveness-Only flows), use the User Image Directory Source customization. See Configuring Liveness-Only Verification (Anchor Image).

Test Cases​

Affirm Deployment Test Cases provides example test cases for validating an Affirm deployment.

Analytics Dashboard​

HYPR Control Center provides an Analytics Dashboard for seeing trends in user verifications. The dashboard allows you to drill down into detailed events to inspect the status of individual user verifications. See Affirm Dashboards for more information.

Activity Log​

The Affirm Activity Log provides a high-level overview of recent verification flows and their results. This is useful for troubleshooting when a user reports an issue during the verification process.

Appendix A: Affirm Capabilities Enabled by HYPR​

The HYPR deployment team enables the following capabilities per tenant. Ask your HYPR representative to enable those your deployment needs:

  • HYPR Affirm (required): core Affirm functionality
  • CC Admin flow type (optional): the CC Admin verification flow type
  • Citrix optimization (optional): Affirm Citrix media redirection optimization
  • International SMS (optional): the SMS delivery service required for sending SMS messages to international users
  • Affirm Helpdesk (optional): Helpdesk access and the verification code shown to the requester
  • Compliance screening (optional): the AML and OFAC check options in Document and Biometric Verification

For the reference list, see the Feature Flags Reference.