Identity Orchestration
What is identity orchestration?
How does identity orchestration work?
- Selects the required checks using the service, user context, and applicable policy
- Coordinates execution by requesting document, biometric, database, or authentication checks
- Interprets results according to each provider's documented meanings and thresholds
- Routes the case to approval, another capture, further verification, rejection, or manual review
- Records the decision with the evidence and policy version used
When does a business need identity orchestration?
How can Regula help with identity orchestration?
FAQ
Is an orchestration platform necessary if a provider offers one API?
A single API may already coordinate several checks. Evaluate what it supports: conditional steps, review routing, policy changes, retries, and useful records. The number of APIs alone does not tell a business whether its coordination requirements are covered.
Can orchestration combine cloud and on-premises services?
Yes, provided the integrations support the required connectivity and data handling. Map which information each service receives, where processing occurs, and how errors return to the case record. The hosting model must be assessed for every component.
What should happen if a required verification service is unavailable?
Policy should define an approved fallback, a pending state, or a delayed decision. A timeout supplies no positive verification evidence. Any alternative provider or method should satisfy the requirements of the check it replaces.
Can scores from different verification vendors be averaged?
Only if a validated decision model supports that use. Scores can measure different things and use different scales. A high face-similarity score cannot compensate for evidence of document forgery merely because an average exceeds a threshold.
Does orchestration require checks to run in a fixed order?
No. Independent checks may run in parallel, and some checks depend on earlier results. Comparing a selfie with a document portrait requires the portrait to be available. Approval should wait for all mandatory checks, regardless of execution order.
How should businesses test changes to orchestration rules?
Use confirmed legitimate and fraudulent cases, technical failures, retries, and review decisions. Compare the proposed rules with the current policy before release. Version the changes and maintain a way to restore the previous configuration if problems occur.