Understanding compliance posture
The Verification page, under Settings, then Verification, has a Posture tab. It gives you two views of your identity-verification configuration: a Your setup summary written in plain sentences, and a Standards mapping you can expand to see how each setting lines up with the standard it relates to. Every row is computed live from your current settings.
This page explains what each status means and how each row earns it.
The four statuses
Section titled “The four statuses”| Status | Meaning |
|---|---|
| Follows | Your configuration matches the standard’s default expectation. The row shows green. |
| Aligned with | Your configuration differs from the default and still respects the standard’s principles. An auditor sees a deliberate deviation with the reasoning shown, and the row stays neutral. |
| Reduced | Your configuration sits below what the standard expects. The row is highlighted so the choice stays visible and deliberate. |
| Not configured | A prerequisite is missing. For the question-based row this means no questions are enabled yet, so question-based verification has nothing to run. |
How a row earns its status
Section titled “How a row earns its status”Each row is recomputed from your settings the moment you change them. The rows you can see:
- NIST SP 800-63A §5.3.2 (KBV procedure): “Not configured” while no questions are enabled. “Follows” when four or more questions are enabled and every applicable one must be answered correctly, which meets the NIST floor of four. “Aligned with” when one to three questions are enabled, a smaller set than the floor.
- NIST SP 800-63B §5.1.3 (OOB principles): appears when the email verification link is turned on, and is always “Aligned with”. The signed email link is modelled on out-of-band principles as a possession factor. NIST reserves §5.1.3 conformance for device-bound authenticators, so aligned-with is the honest status here and the row stays capped there whatever else you configure.
- NIST SP 800-63B §7.2 (session management): “Follows” when a verification stays scoped to the conversation it happened in, which it does by default, with high-assurance re-asked after 30 minutes of inactivity or 12 hours. “Reduced” when you set Cross-channel carry above zero, since a verification then stands beyond the conversation it was earned in. Each channel applies the rule that fits it: a phone call is one continuous session, while an email or chat reasks after a gap.
- NIST SP 800-63B §5.2.2 (rate limiting): reflects Wrong answers allowed and Failed verifications before lockout. “Follows” at three wrong answers or fewer, the NIST floor. “Aligned with” at four or five.
- GDPR Art. 5(1)(e) storage limitation: “Follows” when identity events are retained for 12 months or more, “Aligned with” below 12 months. A scheduled retention sweep runs daily and deletes identity events past each workspace’s configured period, so the storage-limitation claim is enforced in practice.
- NIST SP 800-63B §4 (authenticator assurance): appears as “Reduced” when a channel accepts a caller ID or sender address on its own as identification. A channel signal can be spoofed, so accepting it alone sits below the authentication baseline. The row names the channels where it applies.
- NIST SP 800-63B §5.1.3 (out-of-band authenticators): appears as “Reduced” when an email channel is allowed to deliver the possession link in-band, on the same channel the conversation is already on. The link is still addressed to the address on the customer’s record, so opening it proves control of that mailbox. The row names the email channels where it applies.
Once a National eID country is set up, the Your setup summary names it too: which countries verify through the customer’s own eID app, and, for email channels, whether the approval goes straight to the app or the reply carries a verification link. A completed approval reaches high assurance on its own, and the session rules above apply to it as to every method: a verification stays scoped to the conversation it happened in, and high-assurance is re-asked after the configured inactivity and absolute windows.
When you change a setting, the matching row updates immediately. The posture view has no separate save step.
What auditors see
Section titled “What auditors see”The Posture tab is operator-facing: it is your own view of your configuration. oHallo’s own compliance posture, meaning the DPA addendum, the sub-processor list and security-questionnaire answers, comes from your account contact and stands independent of these per-workspace settings.
The identity events log is the evidentiary record auditors usually request. Open it from the View identity events for this workspace link on the Posture tab. Every verification attempt, every lockout and every successful identification is recorded there with a timestamp.