Identities
Identities brings together, in a single view, the information and activity associated with each registered identity.

From this module you can:
Locate identities using filters.
Check their status and main indicators.
Analyze their risk level and profile maturity.
Review their information and recent activity.
Check associated alerts and blocks.
Access their sessions and related operations.
Review information about privacy and accepted policies.
Check documents, biometric captures, and other associated assets.
Scores, statuses, and alerts help prioritize analysis, but should not be used in isolation to make a decision.
View identities
The main screen shows the identities available in the selected tenant.
Each row represents an identity and summarizes the information needed to identify it and decide whether it requires a more detailed review.

Search and filter identities
Use the filters to narrow the list according to the criteria you need.
You can filter by:
Risk score, to locate identities according to their risk level.
Profile maturity, to distinguish consolidated profiles from those that still have little activity.
Status, to view identities according to their current situation.
The different filters are combined using AND. This means the identity must meet all selected criteria.
The values included within the same filter are combined using OR. For example, if you select the statuses Under review and Flagged, identities with either of the two statuses are shown.
Risk score
The risk score allows you to prioritize identities according to the risk associated with their activity:
Very high: 90–100
High: 70–89
Medium: 40–69
Low: 0–39
The higher the risk score, the greater the need may be to review the identity and its alerts.
Profile maturity
Profile maturity indicates how much the system has learned about the identity's usual activity:
Baseline: the profile has enough information to establish a usual pattern.
Learning: the system continues learning from new sessions.
Insufficient: there are still not enough sessions to establish a profile.
Low maturity does not by itself imply high risk. It may be due to the identity still having little recorded activity.
Status
Status allows you to locate identities according to their current situation:
Verified: the identity appears verified.
Under review: the identity requires or is pending review.
Flagged: the identity has been flagged to make it easier to identify and track.
Interpret the status together with the scores, alerts, and available history.
Remove filters
The selected filters appear above the list.
You can:
Remove an individual filter by selecting its close icon.
Use Clear all to remove all filters and restore the full list.
If you do not find results, remove some of the filters or broaden the selected values.
Results
Each row shows the main data available about an identity.
Depending on the module configuration, you may find information such as:
Identity name or identifier.
Risk score.
Profile maturity.
Status.
Registration date.
Date of the last interaction.
Some data may not be available if it has not yet been received or if the identity has little recorded activity.
The absence of data does not mean the result is negative. It indicates that the information is not available or has not yet been able to be calculated.
Change pages
Use the pagination at the bottom of the list to view more identities.
When you change the filters, the list returns to the first results page.
Open an identity
Select the identity you want to analyze.
Its detail view will open, where you can view all the aggregated information about that person.
Identity detail
The detail brings together the information associated with an identity and organizes it into five tabs:
Customer
Risk
Session history
Privacy
Assets
Select a tab to switch categories. Changing tabs does not modify the identity information.
Header
The header remains visible in all tabs and lets you confirm which identity you are viewing.

It may include:
Name or identifier.
Status.
Identity score.
Profile maturity.
Number of sessions or interactions.
Associated alerts.
Risk score
The risk score represents the level of confidence associated with the identity based on the available information.
The higher the value, the greater the established confidence in that identity.
Select the indicator to open its detail and view additional information, when this action is available.
The risk score cannot be modified from Identities.
Profile maturity
Profile maturity indicates how much the system knows about the identity's usual patterns.
Select the indicator to view its phase and understand whether the profile:
Still does not have enough information.
Is in the learning phase.
Has already established a baseline.
Identity score and Profile maturity are independent indicators. An identity can have a high level of confidence and, at the same time, a not very mature profile if it still has few sessions.
Identity status
Status indicates the identity's current situation and helps prioritize its review.
Interpret it together with the identity score, profile maturity, alerts, and associated sessions.
Customer
Customer provides an overview of the identity and its most recent activity.

Use this tab as a starting point before analyzing the risk or related sessions.
Main information
This section may show:
Identification information.
Available contact details.
Registration date.
Current status.
Identity score.
Profile maturity.
The information is shown in view mode and cannot be edited from this screen.
Recent activity
Recent activity summarizes the latest relevant events associated with the identity.
Use it to identify recent changes or actions before reviewing the full history.
Latest interactions
This section shows the identity's most recent sessions or operations.
Select an interaction when it has a link available to open its related information.
Accepted policies
This section shows the consents or conditions accepted by the identity.
Depending on the available information, you may find:
Policy name.
Version.
Acceptance date.
Status.
Accepted policies cannot be modified from Identities.
Risk
Risk brings together the main indicators, alerts, and events related to the identity's risk.

Use this tab to understand which conditions may require attention and how the risk has evolved.
Risk indicators
The top of the tab may include indicators such as:
Risk profile, which summarizes the identity's security situation.
Accumulated risk, which reflects the accumulated risk during its activity.
Peak session risk, which shows the highest risk recorded in a session.
Security alerts, which indicates the number of associated alerts.
The indicators are a summary. Review the related alerts and sessions to understand what caused each result.
Risk evolution
Risk timeline shows how the identity's risk has evolved over time.
Use it to:
Identify increases or decreases.
Detect sessions with especially high risk.
Relate changes to specific interactions.
When the chart allows interaction, hover over or select a point to view the associated date, value, and session.
Alerts
The tab may show active alerts and recently detected alerts.

Among others, alerts related to the following may appear:
Anomalous devices.
VPN use.
Shared devices.
Unusual behaviors.
Location or network changes.
Select an alert when detail access is available to view:
What condition was detected.
When it occurred.
Which session is related.
What additional information is available.
An alert does not by itself modify the identity or confirm that fraud exists.
Automatic blocks
This section shows the measures automatically activated in response to certain signals or rules.

It may include blocks related to:
Presentation attack detection.
Injection attack detection.
Manipulation attack detection.
Remote access tools.
Review the available information to identify:
What type of block was activated.
When it occurred.
Which session or operation triggered it.
Whether it is still active.
The blocks shown are informational and cannot be modified from Identities.
Session history
Session history shows the sessions associated with the identity.

Use it to review its activity over time and access the detail of a specific interaction.
Session history
Each row can show:
Session identifier.
Tenant.
Associated user.
Session score.
Date and time.
Channel.
Status.
Sessions are presented in chronological order to make it easier to review recent activity.
A session score represents the result of that specific interaction. It should not be confused with the aggregated indicators of the identity.
Open a session
Select View session list in the corresponding row.

The session detail will open in Behaviour, where you can view its signals, alerts, devices, network, location, and events.
When you return to Identities, make sure you are still viewing the correct identity and tenant.
Privacy
Privacy brings together information related to ARCO rights requests and the consents signed by the identity.

This tab may contain personal or sensitive data. Use it only for tasks authorized by your organization.
ARCO requests
This section shows requests related to the exercise of ARCO rights:
Access: access to personal data.
Rectification: correction of inaccurate or incomplete data.
Cancellation: deletion or erasure of data, when applicable.
Opposition: opposition to data processing.
Each request may include information such as:
Request type.
Creation date.
Status.
Resolution date, when available.
Associated additional information.
Open a request
Select a request when detail access is available.
From its detail you can view the recorded information and the current status of the request.
The available actions depend on the permissions associated with your user.
Signed consents
This section shows the consents and policies accepted by the identity.
Each record may include:
Consent or policy name.
Version.
Date and time of acceptance.
Status.
Channel or process in which it was recorded, when available.
Use this information to check which conditions the identity accepted and when each acceptance was recorded.
Open a consent
Select a consent when detail or the associated document access is available.
Signed consents are shown in view mode and cannot be modified from Identities.
Assets
Assets brings together the resources obtained during the identity's operations and sessions.

Associated assets
Depending on the available activity, the following may appear:
Identity documents.
Face captures.
Fingerprint scans.
Other biometric or document resources.
Each asset may include information such as:
Type.
Capture date.
Origin operation.
Status or result.
Available technical information.
Open an asset
Select an asset to open its preview or view its information.
The type of view will depend on the selected resource.
Access the origin operation
When the asset is linked to an operation, select the available access to open its detail in ID Verification.
Use that view to review the full process, the results, and the related evidence.
Limitations
Assets are view-only items:
They cannot be edited from Identities.
They cannot be replaced.
They cannot be manually deleted from this tab.
Their availability depends on the operations performed and the applicable retention policy.
How to investigate an identity
To analyze an identity:
Locate it using the list filters.
Review the header to check its status, Identity score, and Profile maturity.
Consult Customer to understand who it is and what its recent activity has been.
Open Risk to analyze indicators, alerts, and blocks.
Review Session history to identify the related interactions.
Open a session in Behaviour when you need to analyze what happened.
Consult Privacy if the investigation involves consents or personal data.
Review Assets to view documents and biometric evidence.
Access ID Verification when you need to expand the information for an operation.
Do not base a conclusion solely on a score, a status, or an alert.
Last updated