Language

Identity Graph

What is an identity graph?

An identity graph is a data structure that records relationships between identities, identifiers, and associated records. It may connect people with accounts, email addresses, phone numbers, devices, documents, and verification events.
The connections have different meanings. Two records may refer to the same person, or two different people may share a device. A useful graph preserves that distinction so a shared relationship is not mistaken for proof of a shared identity.

How does an identity graph work?

A graph stores items as nodes and the relationships between them as links. A business might connect a customer node to an account, then connect that account to the device used during registration.
Creating reliable links usually requires:
  • Data preparation: Standardize identifiers and exclude empty, invalid, or placeholder values
  • Relationship rules: Define what each connection means and what evidence supports it
  • Confidence assessment: Separate confirmed associations from tentative matches
  • Maintenance: Update or remove links when details change or a previous association proves incorrect
For example, a phone number may be reassigned to a new subscriber. Retaining the date and source of the original association helps prevent an old connection from being treated as current evidence.

How do identity graphs support fraud investigations?

Graphs help investigators examine relationships that separate account records can conceal. Several applications may use different names but share a device, contact number, or destination account. Reviewing these connections together can reveal coordinated activity.

How can Regula support an identity graph?

Regula Document Reader SDK supplies extracted document data and authenticity results that organizations can associate with a customer record.
Regula Face SDK supplies biometric comparison results and supports 1:N identification where database searches are appropriate.
These outputs can support graph links through an integration. The graph's matching rules must still define which records are connected, the confidence in each connection, and whether a reviewer must confirm it.

FAQ

Does a business need a graph database to build an identity graph?

Not necessarily. Relational databases can store identities and their connections. A graph database may be useful when teams frequently investigate several degrees of connection or complex networks. The choice depends on query needs, scale, and maintenance resources.

How do deterministic and probabilistic identity matching differ?

Deterministic matching uses defined rules, such as agreement on an identifier within the same issuing system. Probabilistic matching estimates whether records refer to the same entity using several attributes. Both require validation against known cases.

Can a graph automatically block accounts connected to known fraud?

It can support that decision, but a connection alone may be insufficient. Policy should consider the relationship type, its age, supporting evidence, and possible innocent explanations. A shared address deserves different treatment from confirmed reuse of a compromised credential.

Does hashing identity data make a graph anonymous?

No. Hashed or tokenized identifiers may still be linkable to a person. They require appropriate protection and retention controls. The ICO distinguishes pseudonymization from anonymization and explains when pseudonymized information remains personal data.

Can document-image hashes identify every reuse of an identity document?

No. An ordinary cryptographic hash detects identical file content. A new photograph, crop, or compression can change the hash even when the document is the same. Document-data matching and image-similarity methods address different reuse patterns and have their own error risks.

How should a business measure identity-graph accuracy?

Track incorrect links, missed links, duplicate identities, and corrections confirmed by reviewers. Test shared devices, changed names, recycled phone numbers, and other legitimate complexities. Keep the supporting evidence available so an incorrect merge can be reversed.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules