01 — Getting in
Signing in
The console is at https://admin.idntory.com. Sign in with your
firm slug and your firm password.
northwind) in Firm and your
password below it.A session lasts 7 days. Sign out is in the top-right of every page.
After 3 failed sign-ins from one network address, that address is blocked from signing in — with no on-screen notice; the form keeps saying “Incorrect password”. If you fat-finger your password a few times and then can't get in even when it's right, you've been blocked — contact your idntory administrator to clear it.
02 — The verifications list
The verifications list
This is the landing page. Every completed verification appears here, newest first, with the person's name, country, document type, the system's verdict, and a confidence score.
Filtering & search
- status
- Verified / not verified.
- document
- Passport, national ID, driver's licence, residence permit.
- country
- Start typing and pick from the list — a partial code is ignored.
- date range
- Submitted between two dates.
- search
- Matches the person's name, the document number, or your
user_ref. Typing here also shows a quick jump-to-record dropdown.
Press Filter to apply. Paging controls are at the bottom.
What the verdict badge means
Green is a pass, red is a fail, amber is a pass with a caveat. The exact words come from the pipeline's combined verdict:
| Badge | Verdict | Meaning |
|---|---|---|
| pass | pass | Document, face and (where present) MRZ all matched cleanly. |
| mrz face pass | mrz_face_pass | No reference image on file for this document, but the MRZ and the face both checked out. |
| face only pass | face_only_pass | Face matched; no document or MRZ check was possible. |
| pass mrz warn | pass_mrz_warn | Passed, but the MRZ had a non-fatal warning. Worth a look. |
| both weak | both_weak | Document and face both matched weakly — needs a human decision. |
| face ai mismatch | face_ai_mismatch | The two face models disagreed — a strong fraud signal. |
| mrz unreadable | mrz_unreadable | An MRZ zone was found but couldn't be parsed or checksummed. |
| mrz tampered | mrz_tampered | MRZ check digits didn't validate. |
| liveness fail | liveness_fail | The selfie frames failed the anti-spoof check. |
| fail | fail | Nothing matched. |
Only pass, mrz_face_pass, face_only_pass and
pass_mrz_warn count as verified. Anything else that reaches a
person also gets a second-opinion review by Claude before it lands here.
03 — Reading a verification
Reading a verification
A record has six tabs. Overview is the summary; the rest are the evidence behind the verdict.
Model Scores
Each leg of the check, with the model that produced it. A score tagged heuristic fallback came from a simpler method, not the full model — weight it accordingly.
MRZ Checksums & Printed vs MRZ Cross-Check
For documents with a machine-readable zone: the MRZ Checksums tab shows each ICAO check digit passing or failing. Printed vs MRZ Cross-Check puts the text the OCR read off the front of the document next to the text encoded in the MRZ, so a mismatch (a sign of tampering) is obvious.
Forensics & EXIF Check
Tamper heuristics on the document image — camera metadata, Error Level Analysis, and
named risk flags like missing_exif or an editing-tool signature. A
review verdict here means “look closer”,
not “reject”.
PEP & Sanctions Checklist
The screening run on the extracted name against global politically-exposed-person, sanctions and adverse-media lists.
04 — Making a decision
Approve, reject, correct
The action buttons sit in the top-right of a record: Your name, Edit values, Reject, Approve.
- Put your name in the Your name box — it's stamped onto the record as the reviewer. (Named team members are filled in automatically.)
- Read the evidence tabs. Pay attention to any amber or red leg.
- If the system misread a field, click Edit values, fix it, and save. Your correction is stored as an overlay — the original machine reading is kept untouched for audit.
- Click Approve or Reject. The record is marked reviewed and shows a Reviewed by … badge from then on.
Approving a record the system failed (or rejecting one it passed) is allowed and expected — that's the point of human review. Both the system's verdict and your decision are kept on the record.
05 — Removing records
Deleting & restoring
Delete is a soft delete: the record greys out and can be Restored for 24 hours, after which it is permanently purged automatically. Deleting a record removes its images from storage too. Generated links follow the same 24-hour soft-delete rule.
06 — Onboarding an applicant
Generate Link
A one-time link you send to a person so they can capture their own document and selfie on their own phone. The result lands in Verifications, tagged to the right firm. The link never carries your firm's API key.
- Optionally add an applicant reference — your own ID for this person.
- Click Generate link and send the URL to the applicant.
Each link is single-use and expires after 24 hours. Once opened and submitted it can't be reused.
07 — Checks without a verification
Ad-hoc checks
Three tools for checking someone or something that isn't going through the full capture flow. Each keeps its own audit log and never touches the verifications list.
PEP & Sanctions Check person
Screen a name against the same PEP / sanctions / adverse-media lists the pipeline uses. No document needed.
KYB company
The same idea for a business — screen a company name against sanctions and adverse-media lists, with optional jurisdiction and registration number.
Document Authenticity Check document
Upload a document on file and run the forensics, reference-match / MRZ, and a PEP screen on the name — without a selfie or liveness step. For checking a document you already hold, not onboarding a live person.