Platform · Review console
Give reviewers the evidence, not just a verdict.
Sessions that need a human land in the review queue. A reviewer sees the extracted identity, every check with its score and warnings, the captured images decrypted on demand, and the activity timeline, then approves or declines with a note.
- roles: owner, admin, reviewer, viewer
- 4
- audited record per decision
- 1
- files served publicly
- 0
What it checks
Review console, check by check.
Each rule below is what the engine actually runs.
Evidence in one view
Identity with per-field sources, checks with scores and warnings, images, webhook deliveries and the event timeline of the session.
Decisions are audited
Approvals, declines and overturned decisions are written to the audit log with the reviewer and note, and each emits a webhook.
Least privilege
Viewers read, reviewers decide and create verification links, admins configure apps, keys, workflows and webhooks, owners manage the team.
Verification links
Reviewers can create a session from the console and send the link themselves, without an integration.
Try it
Decide like the engine, then like a reviewer.
Set each check's status and see the rule pick the outcome and the reason. When a session lands in review, approve or decline it and see the audit record and the webhook that follow.
- The rules are ported line for line from the Rust engine, and the page names the file.
- Everything runs locally in this tab. No request is made while you type.
- Reset puts the example back; nothing is saved.
Decision rule and review
Checks, in decision order
- document
- liveness
- face_matchface_match_weak
- aml
- duplicate
- ip
Automatic outcome
face_match_weakface_match needs a person, so the session joins the review queue.
You are the reviewer
Kept on the session and in the audit log.
Logic ported from backend/crates/kyc-api/src/engine/submit.rs · routes/console_sessions.rs. Nothing you type leaves this page.
How it works
What happens, in order.
- 1
Queue
The engine sends sessions to review on weak matches, potential sanctions hits, duplicates, errors or unclear ages.
- 2
Inspect
Images are decrypted only when a signed-in user opens them, with
cache-control: private, no-store. - 3
Decide
Approve or decline with a note. The decision, reviewer and time are added to the session and sent by webhook.
Part of every organisation
Review console needs no workflow setting. Access follows the four roles in the reference below, and every decision is written to the audit log.
Reference
Four roles, least privilege.
| Role | Can |
|---|---|
| viewer | Read sessions, checks, images and the audit log |
| reviewer | Everything a viewer can, plus approve or decline sessions and create verification links |
| admin | Everything a reviewer can, plus configure apps, API keys, workflows, webhooks and sanctions lists |
| owner | Everything an admin can, plus manage the team and the organisation |
Reasons and warnings
Exact codes, as they appear in the check's data and warnings, so you can branch on them.
| Code | Outcome | When |
|---|---|---|
| session.reviewed | audit | Written for every review with from, to, the note and whether it overturned a final decision. |
| manual_review_declined | declined | The decision_reason when a person declines. |
| A note is required to overturn a final decision | refused | Changing an approved or declined session needs a written reason. |
| session.purged | audit | Written when a session's data is deleted from the console or the API. |
API
Decide from your own back office.
If reviews happen in your tools, PATCH /v1/sessions/{id}/status approves or declines a session that is in review, with a note. The API key is recorded as the actor.
Decide from your own back office.
curl -X PATCH https://kycverify.me/api/v1/sessions/ses_…/status \
-H "x-api-key: $KYC_API_KEY" \
-H "content-type: application/json" \
-d '{ "status": "approved", "note": "Checked against the original passport at the branch." }'200 OK · the updated decision
{
"session_id": "ses_…",
"status": "approved",
"decision_reason": "face_match_weak",
"review": { "reviewed_by": null, "reviewed_at": "2026-10-03T09:40:02Z", "note": "Checked against the original passport at the branch." },
"checks": [ … ],
"identity": { … }
}Limits
What it does not do.
Stated up front, so you can decide what to pair it with.
- No case management or multi-step approval chains. One reviewer decision closes the session.
FAQ
Review console: questions.
Can a reviewer overturn an automatic decision?
Yes, and the overturn is audited like any other review decision.
Try it in the sandbox today.
Every check is available from the first sign-up, with test keys and a default workflow. Talk to us when you are ready to verify real people.