Setting Up a Type
A type is where the rules live. It is worth going through the settings deliberately, because two of them change behaviour well beyond the check itself.
Where to find it
Architect Panel → Security:
- User Verification — the console — providers, types, checks and their history
- Permissions — the group awarded on success
Architect Panel → Layout & Pages:
- E-mail Templates — the message sent to the user
The settings
- Category — identity, age or affiliation.
- Provider — who performs the check.
- Provider programme — where a provider offers named programmes.
- Internal domains — for the e-mail domain check.
- Validity days — how long a success lasts.
- Allow re-verification — whether a user may check again.
- Require manual review — whether a person confirms the outcome.
- Gates login — whether sign-in requires this verification.
- Award group — the security group granted on success.
- E-mail template and account, and a link timeout.
- Enabled and sort order.
Award group is the powerful one
A successful verification can place the user into a security group — which is how a verified status becomes actual access rather than a badge.
Because it grants access, treat it with the care you would give any other permission decision. Ask what that group can reach, and satisfy yourself that everybody who passes this check should have it. A generous group behind a lightly-checked verification is a real exposure, and it will not look like a permissions problem when you come to review it.
Gates login is the other one
It prevents sign-in until the verification is held. Powerful, and easy to apply too broadly — see the article on requiring verification to sign in before turning it on.
Validity days
Set it to how quickly the underlying fact changes. Two years is reasonable for identity; one year for affiliation; shorter where the status is genuinely volatile. A validity longer than the fact's natural life means you are relying on something that stopped being true.
Allow re-verification
Generally leave it on. A user whose circumstances changed — a new job, a new document — should be able to check again without an administrator. Turning it off is for the rare case where repeated attempts are themselves a risk.
Link timeout
How long the user has to complete a check after it is requested, in minutes. It ships at 30, which suits somebody who starts immediately. If your users typically receive an e-mail and come back later, that is too short — and an expired link is a support call.
Require manual review
Adds a human decision before the result is accepted. Right for high-value verifications; wrong as a default, because a review queue nobody works becomes a queue of users waiting.
Worked example
A service sets up Healthcare Worker: affiliation, internal domain check against NHS domains, 365 days validity, re-verification allowed, no manual review, does not gate login, awarding the "Verified Clinician" group. The group is checked first — it grants access to clinical content only, nothing administrative — before the type is enabled.
Recommendations
- Review what the award group can reach before setting it.
- Match validity to the fact, not to a convenient number.
- Leave re-verification on.
- Lengthen the link timeout if users receive a link by e-mail.