Ping
Deploy CLEAR within your Ping Identity software to create identity backed workflows.
Overview
Use CLEAR within Ping Identity to create Identity backed workflows across your organizations entire employee lifecycle. With CLEAR + Ping your organization can define touchpoints where ensuring employees are who they say they is critical. From there you can introduce a verification to ensure that employee requesting matches the employee record on file.
How It Works
CLEAR and Ping have distinct responsibilities within the identity and integration workflow:
CLEAR handles identity verification, matching, and future interoperability capabilities, while Ping manages integrations and data mapping.
CLEAR Responsibilities
Identity Verification
Identity verification requirements are determined by the settings configured within each project. To review the verification settings enabled for a specific project, navigate to the CLEAR Console.
CLEAR maintains a baseline identity assurance standard that requires verification across the following components at a minimum:
- Biometric Verification
- Document Verification
- Source Validation
Projects may also be configured with additional verification controls to increase the level of identity assurance based on business or regulatory requirements.
Matching
In addition to verifying a user's identity, CLEAR assists with matching verified users to the user records you maintain within your systems. We refer to this process as User Profile Matching.
User Profile Matching is a critical component of the identity lifecycle. It helps ensure not only that a user is who they claim to be, but also that they are correctly associated with the corresponding user record in your environment.
Once a match has been established, CLEAR and Ping work together to map and store the CLEAR User ID against your user record. This persistent identifier enables streamlined authentication and verification experiences for returning users, supporting faster verification flows for high-frequency use cases while maintaining a high level of identity assurance.
Known User Key Flow
When a user interacts with CLEAR for the first time within your environment, they complete a full identity verification. As part of this process, CLEAR facilitates User Profile Matching and establishes a persistent association between the verified user and their corresponding user record by storing a CLEAR User ID.
Once this interoperable identifier has been established, future verification flows can leverage the Known User Key Flow. In these experiences, users may only need to submit a selfie while CLEAR continues to perform identity proofing and security validation across all applicable verification vectors behind the scenes.
The integration automatically manages this process, intelligently determining whether a user should be routed through a full verification flow or a Known User Key Flow based on the presence of an established CLEAR User ID and user match.
We typically recommend introducing CLEAR during the onboarding process. This allows the user match to be established early, enabling all subsequent use cases to take advantage of the faster Known User Key Flow experience.
However, onboarding is not a strict requirement. If a user first encounters CLEAR through a downstream use case, CLEAR can facilitate User Profile Matching at that point in time. This ensures that the user-to-record association can be established whenever needed, allowing the Known User Key Flow to be leveraged throughout the remainder of the employee lifecycle.
Ping Responsibilities
Integration Infrastructure
Workflow Orchestration: Ping provides the workflow platform where organizations can incorporate CLEAR into their identity journeys. Within Ping, you can define when a CLEAR verification should occur and configure the actions that take place before and after the CLEAR experience.
Credential Management: Ping securely manages the credentials required to integrate with CLEAR, including API keys, Project IDs, and other configuration parameters. These credentials are used to power CLEAR experiences within Ping workflows.
Session Initiation
Ping initiates CLEAR verification sessions based on the order and logic defined within the Ping workflow. When a user reaches the appropriate step in the workflow, Ping triggers the corresponding CLEAR project and experience.
Intelligent Routing
Ping determines which CLEAR verification flow a user should enter based on the data available on their user record. For example, if a user has an existing CLEAR User ID, Ping can route them to a Known User Key Flow. If no CLEAR User ID exists, Ping can route them to a full verification flow.
This routing logic is executed before the user enters a CLEAR session, ensuring that users receive the most appropriate verification experience.
Data Mapping
After a user has been successfully verified and matched, Ping maps the relevant CLEAR data and identifiers back to the appropriate user record within your environment.
Data Storage
Ping is responsible for storing and maintaining user data within your systems. This includes persisting the CLEAR User ID and any other required data elements needed to support future verification and authentication workflows.
Use Cases
- Onboarding
- Multi Factor Authentication
- Conditional Access
- Password Reset
- Account Recovery
Accessibility
Works With
- PingOne Advanced Identity Cloud
- PingAM
- PingOne DaVinci
How to Use
1. Configure the CLEAR Node
Provide the following CLEAR configuration values within the Ping workflow:
Required Credentials
- Establish Identity Project ID
- Known User Key Project ID
- API Key
Custom Field
- Internal organization identifier (for example: Employee ID, User ID, or another unique organizational identifier)
User Profile Information
- First Name
- Last Name
- Date of Birth (if available and applicable)
Providing user profile information improves User Profile Matching accuracy and helps establish the user-to-record association required for future Known User Key Flows.
2. Validate in a Test Environment
Deploy the workflow to a test group and validate the end-to-end experience, including:
- User verification
- User Profile Matching
- CLEAR User ID storage
- Known User Key Flow routing for returning users
- Data mapping and persistence within your environment
3. Launch
Once testing is complete and the workflow has been validated, deploy the workflow to production and make the CLEAR experience available to your target user population.
Considerations
- Instant-On: This is a no-code integration. Your team can plug your CLEAR credentials into the Ping Journey Node
- Change management, employee comms, and socialization should be considered when rolling out identity verification with your organization
Resources
Updated about 2 months ago