Identity Verification Authentication
SigningHub provides an Identity Verification (IDV) feature that enables document owners to verify the identity of recipients before they can open or sign documents. The verification process is performed through an integrated identity verification provider and requires recipients to complete the verification process using the Ascertia Identity mobile application. Identity Verification is dependent on the system license. If the IDENTITY_VERIFICATION module is not enabled in the SigningHub license, the feature will not be available for configuration or use.
How it Works?
Enable the Identity Verification module in your SigningHub license.
Configure an Identity Verification connector in SigningHub Admin.
Configure Identity Verification permissions against the administrator role in SigningHub Admin.
Create an Identity Verification Profile in SigningHub Admin.
Configure the Identity Verification Profile for the service plan in SigningHub Admin.
Configure Identity Verification Policies against the enterprise role in SigningHub Web.
Create an Identity Verification Policy in SigningHub Web.
Configure the allowed Identity Verification Policies against the enterprise role.
Configure the Identity Verification Transactions limit for enterprise users.
Apply Identity Verification to the required document authentication settings in SigningHub Web.
The recipient authenticates using the Ascertia Identity mobile application.
Enable "Identity Verification" in your SigningHub License
The Identity Verification feature will be supported by the system if the "IDENTITY_VERIFICATION" module is enabled in the license. Contact the SigningHub support and request that they enable this module in your license.
Configure a Connector in SigningHub Admin
Make the following configurations to a connector in SigningHub Admin:
In the "Basic Information" section, choose "Identity Verification" as the "Method".

In the "Details" section, fill in the required fields.

Configure the Role of Administrator in SigningHub Admin
Make the following configurations against the administrator role.
From the Details screen, allow the "Identity Verification Profile" module for this role.

The "Identity Verification Profiles" module will only be displayed if "IDENTITY_VERIFICATION" is enabled in the system license. Administrators must explicitly allow this module in a role to enable access to Identity Verification management.
Configure an Identity Verification Profile in SigningHub Admin
Make the following configurations for an Identity Verification Profile in SigningHub Admin:
In the "Consent" section, specify the consent information that is displayed to users during the identity verification process in the mobile application.
In the "Settings" section, specify the identity verification server and provider.

Enable the “Required” option on the “Consent” screen if user agreement to the consent information is mandatory.
Add Identity Verification Profile to a Service Plan
Make the following configurations to a service plan in SigningHub Admin:
Select and add the earlier configured Identity Verification Profile in a service plan in SigningHub Admin:

From the "Constraints" section, add the Identity Verification Transactions constraint.

Enable Identity Verification Policies against an Enterprise Role in SigningHub Web
Make the following configurations against an enterprise role:
From the "Enterprise Access Preferences" section, allow "Identity Verification Policies" against this user role.

Create an Identity Verification Policy In SigningHub Web
Make the following configurations against an Identity Verification Policy:
From the "Add Identity Verification Policy" screen, select the profile and policy.

Configure the Allowed Identity Verification Policies against an Enterprise Role in SigningHub Web
Make the following configurations against an enterprise role:
From the "Identity Verification Policies Preferences" section, allow the desired "Identity Verification Policies" against this user role.

Configure the Identity Verification Transactions Limit for a User in SigningHub Web
To configure the maximum number of Identity Verification transactions that a user can consume, make the following configurations against Users in Enterprise Configurations:
Click the User Preferences option from the right panel against a user.
Expand the Usage and Limits section and specify the required value in the Identity Verification Transactions field.

The "Identity Verification Transactions" constraint option will only be displayed if Identity Verification is enabled in the user's service plan.
Audit logs are maintained for the Identity Verification transactions consumed by the users.
Configuring Identity Verification via SigningHub Web
Identity Verification (IDV) can be applied at different stages of a document workflow in SigningHub Web. Once configured, recipients must complete identity verification using the selected Identity Verification Profile before they can access or sign the document.
Document Access Authentication
To require Identity Verification before a recipient can open a document, configure the "Access Authentication" option in the "Document Access Security" settings.
Select "Identity Verification" as the authentication type and select the "Identity Verification Profile" to be used for verification.

The recipient must successfully complete the verification process defined in the selected profile before the document can be opened.
Document Signing Authentication
To require Identity Verification before a recipient can sign a document, configure the "Signing Authentication" option in the "Document Access Security" settings.
Select "Identity Verification" as the authentication type and select the "Identity Verification Profile" to be used for verification.

The recipient must successfully complete the verification process defined in the selected profile before signing the document.
Field-level Authentication
To require Identity Verification before a signer can complete a Signature or In-Person field, configure the "Authenticate Signer" section in the field properties.
Select "Identity Verification" as the authentication type and select the "Identity Verification Profile" to be used for verification.

The signer must successfully complete the verification process defined in the selected profile before interacting with the field.
Recipient-end Identity Verification
When a recipient attempts to open or sign a document for which Identity Verification has been configured, a QR code is displayed in SigningHub Web.
The recipient scans the QR code using the Ascertia Identity mobile application and completes the verification steps defined in the selected Identity Verification Profile. Once the identity verification is completed successfully, SigningHub automatically allows the recipient to open the document or sign the document, based on the configured authentication. If the verification fails or is not completed, you will not be allowed to access the document.

The recipient can cancel or restart the verification process if required.
During Identity Verification (IDV), the system validates the identity by matching the user name returned from the server with the name of the user being authenticated. In case of an in-person signer, the system compares the name returned by the IDV server with the configured in-person signer name to ensure consistency before allowing access or signing.
Audit logs are maintained for Identity Verification events.
The following Authentication preference will be followed while signing, in case of configuration of field-level Authentication, and Document Signing Authentication:
Field-level Authetication is configuredDocument Signing Authentication is configuredAuthentication preferenceNo
No
-
Yes
Yes
Field-level Authentication
Yes
No
Field-level Authentication
Yes
Yes
Field-level Authentication
Yes
No
Field-level Authentication
No
Yes
Document Signing Authentication
No
Yes
Document Signing Authentication
No
No
Secondary Authentication against the Signing Server
Last updated
Was this helpful?

