Language

Identity Orchestration

What is identity orchestration?

Identity orchestration is the coordination of identity checks, services, and decisions according to an organization's rules. It determines which checks a person needs, how the results affect the next step, and when a case requires additional evidence or review.
An orchestrated process may use one provider or several. Its purpose is to apply the required verification and authentication rules consistently during onboarding, account recovery, and other identity-related interactions.

How does identity orchestration work?

The organization defines the process and its decision rules. The orchestration software then:
  • Selects the required checks using the service, user context, and applicable policy
  • Coordinates execution by requesting document, biometric, database, or authentication checks
  • Interprets results according to each provider's documented meanings and thresholds
  • Routes the case to approval, another capture, further verification, rejection, or manual review
  • Records the decision with the evidence and policy version used
For example, an unreadable passport chip may trigger another reading attempt or an approved alternative. Evidence of document alteration requires a different response. Treating both as the same generic failure makes it difficult to apply the right rule.

When does a business need identity orchestration?

Orchestration becomes useful when requirements vary by product, country, channel, or customer risk. It can also help when several teams maintain separate verification processes or when a business needs controlled fallback between providers.
The operational benefit comes from making policy changes traceable and reusable. Teams can inspect which checks ran and why a customer received a particular decision, including cases that moved between automated processing and human review.

How can Regula help with identity orchestration?

Regula IDV Platform supports configurable verification processes, third-party integrations, customer profiles, and session review. It combines document and biometric capabilities with tools for managing verification steps and the resulting records.
Regula Document Reader SDK and Regula Face SDK can also supply specialized checks to an organization's existing orchestration system. The organization defines required evidence, decision rules, and escalation conditions.

FAQ

Is an orchestration platform necessary if a provider offers one API?

A single API may already coordinate several checks. Evaluate what it supports: conditional steps, review routing, policy changes, retries, and useful records. The number of APIs alone does not tell a business whether its coordination requirements are covered.

Can orchestration combine cloud and on-premises services?

Yes, provided the integrations support the required connectivity and data handling. Map which information each service receives, where processing occurs, and how errors return to the case record. The hosting model must be assessed for every component.

What should happen if a required verification service is unavailable?

Policy should define an approved fallback, a pending state, or a delayed decision. A timeout supplies no positive verification evidence. Any alternative provider or method should satisfy the requirements of the check it replaces.

Can scores from different verification vendors be averaged?

Only if a validated decision model supports that use. Scores can measure different things and use different scales. A high face-similarity score cannot compensate for evidence of document forgery merely because an average exceeds a threshold.

Does orchestration require checks to run in a fixed order?

No. Independent checks may run in parallel, and some checks depend on earlier results. Comparing a selfie with a document portrait requires the portrait to be available. Approval should wait for all mandatory checks, regardless of execution order.

How should businesses test changes to orchestration rules?

Use confirmed legitimate and fraudulent cases, technical failures, retries, and review decisions. Compare the proposed rules with the current policy before release. Version the changes and maintain a way to restore the previous configuration if problems occur.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules