Skip to content

HR onboarding

Confirm a new hire is who they applied as.

Send a verification link with the offer letter. The candidate verifies a document or Aadhaar with liveness on their phone, and HR sees the result and the evidence in the console, with access limited by role.

Recommended workflowHR onboarding
  1. 1Consent
  2. 2Email OTP
  3. 3Aadhaar
  4. 4PAN
  5. 5Liveness

At submit

  • Face match against the Aadhaar photo
  • Duplicate detection
steps the candidate completes
5
console roles to limit who sees what
4
machine rejections with auto-decline off
0

decision.auto_decline: false · a person decides every failure

The problem

What this use case needs from verification.

  • Remote hiring

    When the interview was on video, the first in-person check may be months away. A liveness-backed face match against the document closes the gap.

  • Sensitive data, few people

    Viewers can read results without deciding; only reviewers decide, and every decision is audited.

  • Short retention

    Set the app's retention to the period your policy allows, and the worker purges files, embeddings and identity data on schedule.

Recommended workflow

Steps the person sees, checks that decide.

Every step a workflow turns on is required, so keep a second workflow with the document step (instead of Aadhaar and PAN) for candidates who do not use Aadhaar, and pass its workflow_id. With auto-decline off, nobody is rejected by a machine.

In the hosted flow

  1. 1Consent
  2. 2Email OTP
  3. 3Aadhaar
  4. 4PAN
  5. 5Liveness

At submit

  • Face match against the Aadhaar photo
  • Duplicate detection
  • IP recorded for the audit trail

Keys left out of the config keep their defaults. Paste it into the workflow builder, or read every key on the workflows page.

Workflow config · json
{
  "steps": {
    "email":      { "enabled": true },
    "document":   { "enabled": false },
    "aadhaar":    { "enabled": true, "methods": ["offline_xml", "secure_qr"] },
    "pan":        { "enabled": true },
    "liveness":   { "enabled": true },
    "face_match": { "enabled": true },
    "aml":        { "enabled": false },
    "duplicate":  { "enabled": true }
  },
  "decision": { "auto_decline": false }
}

Signals

What happens when something is off.

Real cases for this industry, the check that sees each one and what the engine records. Codes are exactly as they appear in the decision.

Signals and outcomes
WhenSeen byOutcome
A stand-in attends the video call but not the verificationface_matchfailedface_match_failed, then review
The Offline e-KYC file was downloaded weeks agoaadhaarreviewaadhaar_xml_too_old
Every email code and resend is used upemailfailedemail_not_verified, then review
The same person applies twice under two namesduplicatereviewduplicate_found
UIDAI certificates are missing on the serveraadhaarreviewaadhaar_signature_unverified

Regulatory context

Where the rules meet the product.

Employers verify identity under employment and data-protection law, and Aadhaar has rules of its own. This is context, not legal advice.

Not legal advice. KYCVerify does not certify compliance with any law or regulator. Confirm how each rule applies to you with your compliance team and counsel.

  • Digital Personal Data Protection Act, 2023

    Recognises processing for employment purposes as a legitimate use, but notice, purpose limitation and erasure still apply. Keep retention short and restrict access with the viewer and reviewer roles.

  • Aadhaar as one option

    Since the Supreme Court's 2018 Puttaswamy judgment, private employers generally should not make Aadhaar mandatory. Offer a document workflow alongside the Aadhaar one.

  • UK right-to-work checks

    Digital right-to-work checks in the UK use certified identity service providers. KYCVerify is not a certified IDSP, so it does not replace that check.

What KYCVerify does not settle for you

  • Background screening (employment, education, criminal records) is out of scope.
  • Tell candidates what you verify and for how long you keep it. The legal templates are a starting point, not advice.

Integrate

One call starts it.

Send the url with the offer letter. contact.email pre-fills the email OTP step.

  1. 1Create the session with this workflow and your own reference.
  2. 2Send the person the url, or open it on a device you control.
  3. 3Act on the signed session.status_updated webhook.

Create a session

curl -X POST https://kycverify.me/api/v1/sessions \
  -H "x-api-key: $KYC_API_KEY" \
  -H "content-type: application/json" \
  -d '{
    "workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
    "vendor_data": "candidate-2041",
    "contact": {
      "email": "candidate@example.com"
    },
    "metadata": {
      "requisition": "ENG-114",
      "start_date": "2026-11-02"
    },
    "expires_in_hours": 168
  }'

201 Created

{
  "session_id": "ses_0k3v9x2m4a7qhd8f1rtb",
  "status": "not_started",
  "url": "https://kycverify.me/verify/q3Xf…",
  "session_token": "q3Xf…",
  "workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
  "vendor_data": "candidate-2041",
  "expires_at": "2026-10-10T09:12:44Z"
}

FAQ

Questions.

Do candidates need an account?

No. The hosted link works on its own and expires after 7 days by default.

Build this workflow in the sandbox.

Set up the configuration above in the workflow builder and run a test session in minutes, then talk to us about going live.