Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

Establishing an identity

Creating a record

Imagine creating an account for a photo-sharing application. You enter a name and an email address, choose a password, and submit the form. The application now has a record that represents you. But what does it actually know?

At first, it knows what you provided. The name might be your legal name, a nickname, or something entirely invented. The email address might belong to you, someone else, or nobody at all. Creating the record gives the application a digital representation to work with. It does not automatically make the information in that record trustworthy.

What verification proves

The application might send a verification link to your email address. Following that link provides evidence that you could access messages sent to that address at that time. It does not, by itself, prove your legal name, your age, or that you are the only person with access to the mailbox.

A verification link checks email access at that time. The same account's legal name, age and exclusive mailbox access remain unestablished by this check.
The result supports mailbox access, not every claim in the account. View full-size illustration (opens in a new tab)

How much a service needs to establish depends on what it does. A discussion forum might let you participate under a chosen name. An employer might create your account using information from its hiring process. A service handling sensitive personal records may need stronger evidence connecting an account to a particular person.

Identity proofing

When a service needs that connection, it can use identity proofing: a process for establishing confidence that someone is the person they claim to be. This can involve checking identity evidence, validating information against trusted sources, and determining whether the evidence belongs to the person presenting it. The process should gather the information needed for its purpose while avoiding unnecessary collection.

The Identity proofing lessons, starting with What proofing establishes, follow a clinic through this process: deciding which person is being claimed, checking whether the evidence is genuine and belongs to the applicant, and handling a check that fails or cannot establish enough confidence.

Sources of trust

Different information may also come from different sources. You might choose your own display name, while your employer supplies your department and employment status. Trusting one source for one attribute does not mean trusting it for everything. A useful question is: who supplied this information, what was checked, and why should this system rely on it?

Recognizing a returning user

Once an account has been established, another question follows: how does the system recognize the person or application returning to use it? That is where authentication enters the picture.

Continue to Proving control of an account to explore that next step.

Try it in the Lab

PUT IT INTO PRACTICE

Check your understanding

Try these questions before moving on. If an answer isn't right, use the feedback and try again.

0 of 2 answered correctly

Enable JavaScript to answer these questions and save progress in this browser.

QUESTION 1 OF 2A photo service sends a verification link to an email address, and someone opens it. What does this establish?

QUESTION 2 OF 2A company grants access based on current employment. Which source is most appropriate for that fact?

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

Learn identity