Digital Identity
Multi-agency, multi-stakeholder programs where procurement, compliance, and mission alignment determine success.
This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.
Inside this journey
-
Pre-Sales
Qualify and diagnose before investing in a full evaluation cycle.
-
Qualification
Confirm budget authority, procurement timeline, and regulatory constraints before committing to full discovery and pilot planning.
Qualification Questions
Operational and integration fit
- To size the pilot and integration effort, roughly how many enrollments do you expect per year across pilot and production?
- Which of these describe the primary identity sources or data stores we would need to integrate with?
- Do you currently capture biometrics at enrollment sites, and at what scale?
Compliance and procurement constraints
- Are there regulatory, data residency, or privacy constraints that will shape the solution (select all that apply)?
- Will the platform need to process or store any sensitive categories of data (select all that apply)?
Budget, decision authority, and timing
- Is there an allocated budget or an approved funding range for this program?
- Who is the primary decision owner for a procurement like this (who would sign or sponsor the contract)?
- What is your target milestone for a pilot or go-live and what is primarily driving that date?
-
Enterprise Discovery
Map stakeholders, legacy identity sources, biometric and enrollment workflows, fraud risks, and measurable success criteria for modernization.
Discovery Questions
How this project looks from your desk
- Tell me about the timeline and mandate driving this initiative for your program, and who set it.
- Walk me through the last major decision that committed budget to identity modernization in your organization.
- Who on your leadership team must sign the funding and when is that decision window?
- How many sites or enrollment locations do you expect to include in an initial pilot?
- What single deadline or compliance date would force you to accelerate procurement immediately?
Where identity breaks today
- If an external audit ran your enrollment workflow from intake to issuance, what failure would stand out first?
- Describe the enrollment steps your operators follow on a busy day, including average time per applicant.
- Identify the legacy identity sources your platform must match or merge, and the format they are stored in.
- When a duplicate identity appears in your queue, what is your current adjudication process and average time to resolve?
- Which single technical constraint in your current stack would prevent a pilot from running on schedule?
Who really touches identity
- Who in your organization stands to lose the most if this system changes, and how would they show resistance?
- List the day to day operators at your enrollment sites and how their tasks would change under a new platform.
- Which internal team owns your identity data stewardship and who is their current lead?
- How often do your frontline operators receive formal training and what is the turnover rate among those roles?
- If one stakeholder in your organization vetoed the pilot, could the program proceed without them?
Risk hotspots and regulatory gates
- Name the compliance requirement that you consider most likely to add months to your timeline if overlooked.
- Tell me about your data residency, retention, and encryption rules that will govern your enrollment data.
- Identify the office in your organization that handles privacy and legal approval and the typical review cycle length.
- Estimate the number of security certifications or audits your program must complete before production credential issuance is allowed.
- List any regulatory approvals your program still needs that would block a pilot.
Other paths you are weighing
- Describe what would have to be true about your current approach for you to keep it rather than change.
- Select the types of alternatives you are considering for your identity program.
- Has anyone on your staff proposed solving this without an outside vendor, and if so what was their main argument?
- Name the alternative that would immediately stop your procurement if it met your needs.
Can your people and systems support a pilot?
- Point to the single integration dependency in your environment that, if missing, would stop technical work from starting.
- Provide the names of the APIs or data endpoints in your systems that must be available and their owners.
- State the number of engineers or project resources you can commit to integration and for how many months.
- Point out the data source in your estate you consider highest risk for quality issues and explain why.
- Do you have physical site constraints at your enrollment locations, such as power, network, or access limitations, that could delay rollout?
- Specify the single readiness item in your program that must be fixed before a pilot can begin and who will own it.
Pilot success criteria that move decisions
- Pick the pilot metric that, if unmet, would cause your leadership to cancel the program.
- Select the measurable acceptance criteria you want validated in your pilot.
- Provide the names of the individuals or roles in your organization that must sign pilot acceptance and the evidence format they will accept.
- Explain how your team will measure demographic fairness and whether you can share historical false reject rates by cohort.
- State the internal step in your approval process that would still block immediate contract approval even if the pilot proves the agreed accuracy and throughput.
Next steps and decision triggers
- Imagine the procurement timeline for your program shortened by 30 days, what commitment would you need from a vendor?
- Indicate the contracting vehicle or procurement path your organization plans to use.
- When is budget available for your multi-phase rollout and is it already allocated?
- Confirm the role in your organization with final signature authority and whether they can sign within two weeks of pilot acceptance.
- Outline the single fastest path to a signed contract after pilot acceptance in your organization and who will execute it.
-
-
Solution Evaluation
Run a pilot evaluation against agreed acceptance criteria (biometric match accuracy, deduplication, integration, and throughput) to establish decision readiness.
- desired_state
- success_criteria
- gaps
- stakeholders
- current_state
- decision_readiness
- gaps
- desired_state
- stakeholders
- success_criteria
- decision_readiness
- current_state
- stakeholders
- decision_readiness
- success_criteria
- current_state
- desired_state
- gaps
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
-
Solution Scope
Define modules, responsibilities, data migration boundaries, integration touchpoints, and measurable acceptance criteria for the full rollout.
Scope Configuration
- Deploy biometric enrollment stations
- Install FIPS-validated cryptography modules
- Configure document authentication engine
- Enable remote identity proofing (mobile/web)
- Integrate legacy enrollment databases
- Migrate applicant identity records with deduplication
- Run biometric deduplication and identity resolution
- Integrate watchlist and third-party database checks
- Implement interoperability APIs and endpoint connectors
- Set up secure credential personalization and issuance
- Activate credential lifecycle management (suspend/revoke)
- Deliver enrollment operator training and SOPs
Scope Questions
Deploy biometric enrollment stations
- How many enrollment stations will you deploy initially (by site)?
- Select the biometric capture modalities each station must support (face, fingerprint, iris, palm, multimodal).
- List the physical interfaces required at each site (network, power redundancy, card printer, secure cabinet).
- Are any sites required to use FIPS 140-2 validated hardware security modules (HSMs) or separate secure enclaves?
- Who is the local owner for station installation and physical security at each site (role/title)?
- Specify the operator throughput target per station (applicants per hour) for capacity planning.
Install FIPS-validated cryptography modules
- Which FIPS validation level is required for cryptographic modules (Level 1, 2, 3, 4)?
- Do you require hardware security module (HSM) deployment on-premises, cloud-hosted, or hybrid?
- Provide your key management policy requirements (rotation frequency, split-key custody, backup retention).
- Identify the certificate authority type that will issue signing certificates for credential personalization (internal PKI, external CA).
- Specify the cryptographic algorithms and key lengths mandated by your compliance policy (for example, RSA 2048, ECDSA P-256).
Configure document authentication engine
- Select the government-issued document types the engine must validate (driver's license front/back, passport MRZ, national ID card).
- Indicate the minimum document verification checks required (MRZ, hologram, barcode, OCR data consistency).
- Do you require support for specific document standards such as ICAO Doc 9303 or ISO/IEC 18013?
- List the languages and character sets OCR must handle for your applicant population.
- How will document template updates be accepted (periodic feed, manual upload, vendor-managed updates)?
Enable remote identity proofing (mobile/web)
- Which NIST SP 800-63 identity assurance level is required for your remote identity proofing (for example IAL2, IAL3)?
- Provide the mobile platforms and browser versions that must be supported for remote enrollment (example iOS versions, Android versions, Chrome, Safari).
- Choose acceptable selfie and liveness checks (passive liveness, active challenge, short video capture).
- Identify the fraud-risk signals or third-party data sources required during remote proofing (credit bureau, phone carrier, device reputation).
- State the target remote enrollment retry rate (percent) to use for capacity and remediation planning.
Integrate legacy enrollment databases
- Catalog the legacy database systems to integrate and their data export formats (SQL dump, CSV, LDAP, proprietary).
- Describe which identity attributes require real-time synchronization versus batched updates (biometric templates, demographics, status flags).
- Estimate the size of each legacy database in records and GB.
- Are legacy databases protected by PII controls that restrict export (column-level encryption, tokenization)?
- Who will own API endpoints or database credentials for integration and what is the expected timeline for credential handover (role/title and date)?
Migrate applicant identity records with deduplication
- What migration completeness target should be used for go-live (for example 95% of legacy records reconciled)?
- Choose the deduplication sensitivity required for flagging potential duplicates (high sensitivity, balanced, high specificity).
- State any historical retention windows or record exclusions for migration (for example records older than 5 years, revoked credentials).
- Enumerate the fields that must be preserved verbatim during migration (biometric templates, original enrollment timestamps, audit trail).
- Describe the manual adjudication workflow for suspected duplicates (roles, SLA for review, review tools required).
Run biometric deduplication and identity resolution
- Declare the 1-to-many deduplication accuracy metrics the system must meet (False Match Rate target, False Non-Match Rate target).
- Estimate peak throughput required for deduplication (1-to-N comparisons per second) based on your population size.
- Name the biometric template formats that must be supported (for example ISO/IEC 19794-2 for fingerprints, 19794-5 for face).
- Outline how probabilistic matches below threshold should be handled (auto-merge, manual review using enrollment photos, quarantine).
- Name the adjudication authority for resolved identities (role/title) and the audit records that must be retained.
Integrate watchlist and third-party database checks
- Catalog the watchlists and third-party databases to check during enrollment (terrorist watchlist, sanctions lists, local criminal records).
- What update frequency and latency do you require for watchlist feeds (real-time, hourly, daily)?
- Confirm if encrypted feeds are required for watchlist queries and responses.
- Define the response-handling rules for positive hits (deny enrollment, escalate to security, continue with warning).
- Record the legal consent artifacts that must be captured and stored when querying third-party databases (consent form, audit signature, timestamp).
Implement interoperability APIs and endpoint connectors
- Detail the systems that must be integrated via APIs at go-live (credential issuance system, legacy database, document management, payment gateway).
- Detail the API protocols and message formats required (REST/JSON, SOAP/XML, gRPC, bulk CSV).
- Confirm the authentication scheme required for connectors (OAuth2, mutual TLS, API key, SAML).
- Confirm whether API-level SLAs for latency and availability are required for each connector.
- Assign the owner for integration endpoint documentation and test sandbox provisioning (role/title).
Set up secure credential personalization and issuance
- Clarify the credential form factors to be issued (plastic ID card with secure chip, printed card, mobile credential).
- Enumerate the personalization hardware required at sites (card printer model, smartcard encoder, secure laminator).
- Clarify the personalization data elements to include on the credential (photo, name, DOB, machine-readable zone).
- Define the security controls to enforce during personalization (HSM signing, sealed personalization room, dual operator).
- Declare the acceptance test that will confirm secure issuance (test credential verification via PKI chain, sample issuance audit).
Activate credential lifecycle management (suspend/revoke)
- Outline the lifecycle events that must be supported and the notification rules for each (suspend, revoke, reissue, expire).
- Record the required propagation time for revocations to downstream services (near-real-time, within 15 minutes, hourly, daily).
- Explain which systems will consume lifecycle events (access control, benefits systems, border control).
- Report the audit retention policy required for lifecycle actions and access logs (1 year, 3 years, 7 years, custom).
- Authorize the roles that can request emergency revocations and document the approval workflow that applies.
Deliver enrollment operator training and SOPs
- Report the operator roles requiring training and expected class size per cohort.
- Recommend the training modalities you prefer (in-person workshop, virtual instructor-led, self-paced e-learning).
- Explain which SOP documents must be included (capture checklist, data handling procedures, privacy notices).
- Recommend the target pass rate on practical enrollment assessments to guide planning (for example 80%, 90%).
-
Mutual Commit
Finalize commercial and legal terms, confirm compliance and data-handling commitments, and lock governance, milestones, and acceptance gates.
Agreement Modules
- Master Services Agreement (MSA)
- Statement of Work (SOW)
- Subscription Agreement / Order Form
- Service Level Agreement (SLA)
- Data Processing Agreement (DPA)
- Public-Sector Procurement & Security Rider
- Acceptance Criteria Annex
- Change Order Agreement
- Transition & Offboarding Plan
- Final Acceptance Certificate
-
Deployment
Operationalize rollout with readiness checks, execution, and outcome validation.
-
Pre-Deployment Readiness
Confirm site selections, operator training plans, data access permissions, and named owners required before configuration and provisioning.
Pre-Deployment Questions
Environment and site access
- Have final deployment sites been selected and approved (we need site-level sign-off before provisioning)?
- List each selected site as: site name, city, on‑site primary contact (name and role) and best contact method — one site per line (so we can schedule hardware delivery and provisioning).
Data and integration readiness
- Has a named owner been assigned for the enrollment/source data migration and approval of migration scope?
- Provide the named data owner(s) for migration (name, role, email) — the deployment team will route migration approvals to these contacts.
- Are production integration endpoints and test environments available for each external system the platform will connect to (identity sources, credential authority, fraud database, or payment gateway)?
- If endpoints are planned or vendor coordination is required, list each system category and the target availability date or current blocker (system category and date/blocker).
People and ownership
- Are operator training materials, curriculum owner, and first-run schedule finalized?
- Provide the named owner(s) for operator training and the planned first training date (name, role, email, date) — required so we can prioritize site onboarding.
Timing and deployment constraints
- Are there blackout windows, regulatory approval dates, or procurement milestones that will restrict provisioning or cutover?
- If yes or unsure, list the constraint and its impact (brief: constraint type, date or approval milestone, and how it restricts deployment) so we can lock a compliant schedule.
-
Configuration Details
Lock exact configuration values the deployment team will use — integration endpoints, migration mappings, hardware specs, and credentials.
Configuration Details
Locking Environments & Endpoints
- Enter the production platform instance name the deployment will create/use (free text; this exact value will be used in monitoring, DNS, and inventory)
- Enter your production API base URL (format: https://api.example.gov/ — include protocol and trailing slash if applicable)
Integration Version & Runtime
- Select the integration/platform release to install in production (choose the exact build variant the deployment will provision)
- If you selected 'Other' above, enter the exact release tag or build identifier the deployment must lock to (free text — e.g., release-2026-07-15)
Integration Connectors & Authentication
- Which type of buyer identity provider (IdP) will the platform integrate with for operator/admin SSO?
- Enter the IdP connector identifier the deployment will configure (free text — entity ID, client ID, or connector name as represented in your IdP)
Data Migration & Field Mappings
- Provide the canonical source-to-platform migration mapping file location the migration job will consume (format: S3 URI, HTTPS URL, or network file path — e.g., s3://bucket/mappings.csv or https://files.example.gov/mapping.json)
- Specify the single source field name in the legacy system that maps to the platform's primary identifier 'global_id' (exact field name, free text)
Provisioning, Hardware & Thresholds
- Select the enrollment-site hardware spec the deployment should provision/configure per site (this value drives imaging and driver selection)
- Number of initial production sites to provision now (numeric — enter integer; default is 3)
- Deduplication match threshold percentage to enforce in production (numeric — enter integer 0-100; Default is 98)
-
Deployment
Execute the phased rollout with per-site provisioning, interoperability testing, operator onboarding, and escalation paths.
-
Go-Live Validation
Verify acceptance gates are met — deduplication thresholds, integration interoperability, operator competency, and stakeholder sign-offs — before full population issuance.
Checklist items
- Receive deduplication validation report meeting agreed acceptance thresholds
- Obtain integration interoperability test report for all integration endpoints
- Collect operator competency sign-offs for all production operators
- Secure per-site go-live acceptance forms for each enrollment location
- Document and test rollback point and recovery procedure
- Receive final data migration reconciliation report
- Obtain security and compliance checklist sign-off
- Publish and distribute final cutover schedule with confirmed escalation contacts
- Verify monitoring, alerting, and support procedures are active and tested
- Receive formal written go/no-go decision from the designated buyer approver
-
-
Success
Track outcome metrics against success criteria, capture lessons learned, and maintain a shared channel for issues and enhancement requests.
Success Reviews
- Go-live Health Check (Week 1-4)
- First Measurement Review (Week 4-10)
- Acceptance Gate Review and Formal Acceptance (Day ~90)
- Operational Burn-down and Lessons Learned (Monthly, Weeks 90-180)
- Quarterly Realization Review (Ongoing quarterly after stabilization)
Issues & Enhancements
- Publish the lessons learned summary and updated operator training materials.
- Produce a documented acceptance decision against the numeric targets recorded in Solution Scope, with pass/fail recorded per criterion.
- If any criteria failed, create a timeboxed remediation plan with verification checkpoints and expected re-evaluation dates.
- Publish the acceptance decision record with the buyer's named signatory and timestamp to the shared workspace.
- Create remediation tickets for any failed criteria and schedule verification checkpoints.
- Publish incumbent decommission confirmation and legacy data archive report.
- Remediation item burn-down
- Reduce the count of critical remediation items to zero and demonstrate measurable improvement in false rejection rate and operator proficiency.
- Capture and publish a lessons learned summary and update operational runbooks and training materials.
- Close or re-schedule remediation tickets with updated ETAs and verification steps.
- Re-confirm acceptance criteria and owners
- Update the enhancement request log with ranks and estimated delivery quarters.
- Outcome metrics vs targets
- Confirm the solution continues to meet acceptance targets for deduplication and interoperability or document required roadmap changes.
- Agree the prioritized enhancement backlog and delivery windows for the upcoming quarter.
- Publish the quarterly metrics report with trend lines and any corrective plans.
- Publish the prioritized enhancement backlog with estimated delivery quarters.
- If any legacy retention or decommission items remain open, schedule a closure checkpoint before the next quarterly review.
- Deployment verification status confirmed and any critical gaps documented with owners and target resolution dates.
- Operator onboarding progress and initial enrollment counts established as the baseline for the next measurement.
- Publish the deployment validation and migration completion report to the shared channel.
- Document the open issue register with owners and target resolution dates.
- Collect and circulate raw enrollment logs needed for first measurement (time per enrollment, enrollments processed).
- Present first data against key metrics
- Determine whether biometric match accuracy and mean enrollment time are trending toward the targets recorded in Solution Scope, or document required corrective actions.
- Create a prioritized remediation plan with resolution dates that positions the project for the acceptance gate.
- Produce a data-backed root cause analysis for each metric gap with sample evidence and suggested fixes.
- Publish the remediation plan with target resolution dates and the expected re-measurement window.
- Confirm the data extracts and dashboards that will be used for the acceptance gate decision.
- Restate acceptance criteria and numeric targets
- Deployment and migration validation
- Present outcome data against each criterion
- Root cause diagnosis for any gaps
- Measure operational metrics and trends
- Persistent issues and operational risk review
- Prioritize enhancement backlog
- Document pass/fail per criterion and formal acceptance decision
- Capture lessons learned and process fixes
- Agree corrective actions with resolution dates
- Early adoption signals and usage patterns
- Update enhancement request log and shared issue channel
- Confirm archival and retention posture
- Incumbent system decommission and data migration closure
- Confirm readiness path to acceptance gate
- Open issues and blockers with owners
- Agree immediate remediation actions
- Agree remediation items and resolution timeline for any failed criteria