Skip to content
imper.ai

Verification Policies

Verification Policies let admins define which verification questions and rules apply to each department, instead of using a single configuration organization-wide. Departments that handle more sensitive requests - for example, Finance - can be held to a stricter policy than general staff.


Accessing Verification Policies

Go to Settings > Verification Policies to see the list of policies configured for your organization, along with the departments each one is assigned to and when it was last updated.

Verification Policies list page, showing the policy table and the New Policy button.

How Policies Work

  • Every organization starts with a Default policy, which cannot be deleted. It guarantees that any department not explicitly assigned to another policy still has a working configuration.
  • A policy can be assigned to one or more departments, but each department can only be assigned to a single policy at a time.

Managing Policies

Creating a Policy

Click New Policy, give it a name, and assign the departments it should apply to.

New policy form with an empty Policy Name field and the default Questions table.

Editing a Policy

Click Edit on a policy to change its name, assigned departments, or configuration (see Policy Settings below). Click Save - a "Changes saved" confirmation appears.

Deleting a Policy

Click Delete policy on the policy you want to remove. A confirmation dialog names the departments it currently applies to: "This policy currently applies to [departments]. Once deleted, users associated with groups will be verified using the Default policy instead. Are you sure?" Choose Cancel or Delete. Once deleted, a "'[Policy]' policy deleted" confirmation appears.

NOTE

The Default policy cannot be deleted.


Policy Settings

Each policy has its own configuration:

SettingDescription
Policy NameIdentifies the policy in the list and when assigning departments.
Assigned DepartmentsThe departments this policy applies to. Each department can belong to only one policy.
If medium risk detected - applyWhat happens when a user in this policy fails verification with medium risk. See Configuring the Medium-Risk Escalation below.
Number of verification questionsHow many dynamic questions a user must answer as part of verification under this policy.
Maximum number of incorrect answers allowedHow many wrong answers are tolerated before verification fails.
Require a dynamic question to start verificationWhen enabled, verification must begin with a dynamic question rather than relying on silent checks alone.
Automatic Question OptimizationWhen enabled, imper.ai automatically adjusts which questions are asked to improve coverage.
QuestionsThe list of verification questions available to the policy, with their data source, coverage, and type. Individual questions can be excluded.
Policy edit screen showing Policy Name, Assigned Departments, and the Questions table.

Configuring the Medium-Risk Escalation

The If medium risk detected - apply setting decides what happens when a user covered by this policy fails verification with medium risk - an uncertain result that isn't safe to pass automatically, but also isn't high-risk enough to block outright. Choose one of three options:

  • None - no escalation option is offered. A medium-risk failed verification is treated the same as any other failure.
  • Verify with Manager - the agent can confirm the user's identity through the user's manager by email. See Verify with Manager for the full flow.
  • Verify via Document - the agent can confirm the user's identity through a government-issued document. See Verify with Document for the full flow.
Verification policy edit screen with the If medium risk detected - apply dropdown open, showing None, Verify via document, and Verify with manager options.

Because this is set per policy, different departments can be configured differently - for example, field employees could use document verification while other departments verify with a manager instead.


Important Notes

  • In this initial release, verification data sources cannot be configured per policy - every policy uses the same organization-wide data sources.