Evidence escalates by risk
Authoritative email, directory, registry, or manual confirmation comes first; credential or residency material, government ID, and liveness are progressively limited to claims that require them.
Verification is optional for ordinary participation and is requested only when a role, authority, residence, expertise, or other claim needs added assurance.
Authoritative email, directory, registry, or manual confirmation comes first; credential or residency material, government ID, and liveness are progressively limited to claims that require them.
Didit, WorkingPolicy's identity-verification processor, should receive evidence directly, including any ID image or selfie/liveness capture. WorkingPolicy is designed not to receive or retain raw IDs, selfies, biometric templates, document numbers, or extracted attributes.
Provider evidence targets deletion seven days after final decision. Thirty days is the maximum documented exception for active appeal, fraud investigation, legal hold, or another binding requirement. WorkingPolicy separately keeps only its own verification-case metadata (status, claim type, timestamps, non-sensitive reason codes) for auditability.
Automation failure does not prove fraud. Anyone who lacks a conventional government ID, cannot complete a selfie or liveness step, or holds nonstandard identification can request manual review instead. The ordinary appeal target is ten business days.
Verified roles generally expire at 12 months or sooner when a credential expires or an event makes the claim stale. Expiry removes the badge and role action, not the account. Declining verification only withholds the associated role or action; it never affects ordinary account standing.
The request screen must identify the claim, evidence tier, provider, retained metadata, public label, expiry, and appeal path before submission.