Each type has a card in the Verification Types section of Architect Panel → Security → User Verification.
The settings
- Name and description — the description is shown to the user before they start, so use it to explain what they will be asked for.
- Category and provider — what kind of check, and who performs it.
- Programme settings — identifiers the provider supplies for this particular programme, plus options such as requiring a selfie.
- Allowed e-mail domains — internal provider only.
- Validity (days) — how long a pass lasts. Zero means it never expires.
- Allow re-verification — whether a user may try again after being rejected.
- Require manual review — hold every pass for an administrator to confirm.
- Gates sign-in — block sign-in until this type passes. Read the article on gating first.
- Award security group — the group associated with passing.
- E-mail template, account and link timeout — internal provider only.
You cannot enable something that cannot work
An unconfigured type would otherwise fail at the exact moment a real customer tried to use it, so enabling is checked first. You are stopped, with an explanation, if no provider is chosen, the provider is switched off, the provider cannot perform that category, or the internal provider is selected without domains and e-mail settings.
About the award group
ActiveManage records which group is associated with a pass but does not add users to it automatically. Your application decides what to grant. That is deliberate — a verification result should not silently change somebody's permissions. If you want the group applied automatically, set it up as a rule or workflow so the decision is visible and auditable.
Worked Examples
- Student discount: 365-day validity, re-verification allowed, no manual review, award group "Students".
- Seller onboarding: ID check with manual review on, 730-day validity, gating the seller area only.
- One-off age gate: validity zero so it never expires, no manual review.