Operate
Console and roles
The review queue, the four roles and what each may do, and what the audit log records.
The console is where your team configures apps and workflows, follows sessions and decides the ones that need a person. Every query it makes is scoped to the signed-in user's organisation.
Roles
Roles are ordered: each includes everything the one before it may do.
| Action | Viewer | Reviewer | Admin | Owner |
|---|---|---|---|---|
| See sessions, decisions, evidence images, statistics | Yes | Yes | Yes | Yes |
| Decide sessions in review | Yes | Yes | Yes | |
| Create verification links | Yes | Yes | Yes | |
| Screen a name against AML lists | Yes | Yes | Yes | |
| Manage apps, API keys, workflows and webhooks | Yes | Yes | ||
| Redeliver webhooks, refresh AML lists, purge sessions | Yes | Yes | ||
| Add and remove team members, change roles | Yes |
The review queue
Sessions in in_review wait in the queue with their decision_reason. A reviewer sees the document images, the selfie and liveness frames, each check's data and warnings, the extracted identity and the event history, then approves or declines with a note. The decision is recorded with the reviewer and time, audited as session.reviewed, and sent as a webhook.
Audit log
| Area | Actions recorded |
|---|---|
| Sign-in | auth.signup, auth.login, auth.login_failed, auth.logout |
| Keys | api_key.created, api_key.revoked |
| Apps and workflows | app.created, app.updated, workflow.created, workflow.updated, workflow.archived |
| Webhooks | webhook.secret_rotated, webhook.test_sent, webhook.redelivered |
| Sessions | session.link_created, session.reviewed, session.purged |
| Team | team.member_added, team.role_changed, team.member_removed |
| AML | aml.refresh |
Each entry keeps the actor, the target, the IP address and a JSON detail. Session-level events (consent, steps, checks, transitions) are kept on the session itself and shown in its history.
Console sign-in
- Passwords are hashed with Argon2id.
- A console session is 32 random bytes in an HttpOnly, SameSite=Lax cookie (Secure over HTTPS), stored as a SHA-256 hash, valid 7 days.
- Sign-in is limited to 10 attempts a minute per IP and email, and failures are audited.