Identity Graph
What is an identity graph?
How does an identity graph work?
- Data preparation: Standardize identifiers and exclude empty, invalid, or placeholder values
- Relationship rules: Define what each connection means and what evidence supports it
- Confidence assessment: Separate confirmed associations from tentative matches
- Maintenance: Update or remove links when details change or a previous association proves incorrect
How do identity graphs support fraud investigations?
How can Regula support an identity graph?
FAQ
Does a business need a graph database to build an identity graph?
Not necessarily. Relational databases can store identities and their connections. A graph database may be useful when teams frequently investigate several degrees of connection or complex networks. The choice depends on query needs, scale, and maintenance resources.
How do deterministic and probabilistic identity matching differ?
Deterministic matching uses defined rules, such as agreement on an identifier within the same issuing system. Probabilistic matching estimates whether records refer to the same entity using several attributes. Both require validation against known cases.
Can a graph automatically block accounts connected to known fraud?
It can support that decision, but a connection alone may be insufficient. Policy should consider the relationship type, its age, supporting evidence, and possible innocent explanations. A shared address deserves different treatment from confirmed reuse of a compromised credential.
Does hashing identity data make a graph anonymous?
No. Hashed or tokenized identifiers may still be linkable to a person. They require appropriate protection and retention controls. The ICO distinguishes pseudonymization from anonymization and explains when pseudonymized information remains personal data.
Can document-image hashes identify every reuse of an identity document?
No. An ordinary cryptographic hash detects identical file content. A new photograph, crop, or compression can change the hash even when the document is the same. Document-data matching and image-similarity methods address different reuse patterns and have their own error risks.
How should a business measure identity-graph accuracy?
Track incorrect links, missed links, duplicate identities, and corrections confirmed by reviewers. Test shared devices, changed names, recycled phone numbers, and other legitimate complexities. Keep the supporting evidence available so an incorrect merge can be reversed.