Why we built it
Built for our own compliance first
We run a voice platform, and FCC rules require a voice provider to know who its customers are on an ongoing basis — not once at signup. So we built verification for ourselves: confirm a person against a government ID, keep a clean record of when and how, produce it on request.
Personnel verification obligations show up in plenty of other places. Since we had to solve it anyway, we are opening it up. The rest of this page is what it does.
Before access is granted
An initial verification with a valid photo ID shown and a live image captured — before anyone touches a production system.
On a recurring cadence
Repeat checks on whatever period you are held to — quarterly is typical — landing at times nobody can anticipate, because a fixed date defeats the purpose.
On demand, on a clock
Someone names a person and expects a completed check inside a short window, with a record they can inspect afterwards.
At a glance
Specifications
| Verification methods | Witnessed live session with a named reviewer · automated document-and-live-image check · either can serve the initial or a recurring check |
|---|---|
| Documents | Government-issued photo ID — driver's license, state ID, passport |
| Scope source | A directory or platform group you already maintain, so joiners enroll and leavers drop out automatically. Manual add and remove as an override |
| Cadence | Configurable period — quarterly is typical. Recurring checks are drawn at unpredictable points inside each period, never a fixed date |
| Spot checks | Random sampling at a configurable rate, excluding anyone verified inside a cooldown window |
| On demand | Any named individual can be requested; the deadline clock starts automatically and pauses for approved absence |
| Cross-check | Name, date of birth and address read from the ID compared against your record. Verdict retained, extracted values discarded |
| Recorded per check | Date and time · method · outcome · who performed it · which checks passed · check reference · consent version |
| Not recorded | No photographs, no face templates, no ID images, no biometric data of any kind |
| Outputs | Per-person status · roster attestation for any past date · exportable evidence for an auditor |
| Where it runs | The JPtheGeek client portal, scoped per client organization with its own roster, policy and records |
| Individual experience | A link by email. No portal account, no app to install, no login to create |
How it works
Four moving parts, one audit trail
You tell us who is in scope. Everything after that is scheduled, chased, recorded and reportable.
Define who is in scope
Scope follows a group you already maintain — a directory group, a team, a customer engagement — so it stays live. Someone joining is enrolled automatically; someone leaving drops out. No spreadsheet that is wrong within a month, and a defensible answer when an auditor asks how you know that is everyone.
Verify before access
The first check is a witnessed one. A manager or HR contact observes the person, sees their government photo ID, and attests to the match — in whatever meeting tool they already use. We do not host the video. What Identity captures is the attestation: who observed whom, when, by what method, and exactly what they affirmed.
Keep verifying — on a schedule nobody can predict
Recurring checks are drawn at unpredictable points inside each period, never a fixed date. Random spot checks run on top. A request for a specific person starts a clock automatically, with approved absence pausing it rather than silently running it down.
Hand over the evidence
Every check produces a record. Any point in time produces an attestation: who was in scope, who is current, who is overdue, and the evidence chain behind each verdict — exportable for your customer or their auditor.
Verification methods
Two ways to satisfy the requirement
Many agreements name a witnessed session as the default and allow an automated method where it is approved. Identity supports both, and records which was used for every check.
A live session, recorded as an attestation
The session happens in your own meeting tooling; Identity records the structured attestation — observed by whom, when, which document type, and what was affirmed.
- Satisfies the standard as literally written — no prior approval needed
- The reviewer is recorded by name on the evidence record
- Run by your own managers or HR — nothing new to learn, no video to host
- Works for the initial check and for recurring checks
Document and live-image check
A self-service link. The individual photographs their government ID and takes a live image; the check runs in seconds and returns a verdict.
- No scheduling, no reviewer time — scales to hundreds of people
- Runs on our own infrastructure — no third-party verification vendor in the path
- Typically requires your customer's written approval as an alternative method
- Falls back to a witnessed session whenever anyone prefers it
If an individual declines the automated check, that is not a refusal to be verified — they are choosing the witnessed method, which is the default the agreement already contemplates. Identity treats those as two different outcomes, records them differently, and never reports someone as having refused verification when they simply asked for a person instead of a camera.
What gets checked
Three things have to agree
A photo of a face next to a photo of a card is a weak check. The strength comes from making the document, the person and your own records corroborate each other.
The document agrees with itself
A modern ID carries the same identifying data in more than one place, and more than one image of the holder. Those have to match each other. Tampering usually shows up here first — and it needs no outside data to detect.
The document is physically present
Capture is a short sequence rather than a single photo, which is what distinguishes a card held in a hand from a screen, a printout or a photocopy.
The person is live and responding
Prompts are issued in an order chosen fresh each session, so a recording cannot answer them. Natural movement over the capture confirms a real person rather than a still image.
A check that passes clearly is done. Anything ambiguous is escalated to a witnessed session rather than guessed at — because no automated system is a match for a determined impersonation attempt, and a person on a short call is. Automation carries the routine majority; judgement handles the rest.
Thresholds are deliberately set to escalate generously. A false alarm costs one brief call. The other kind of mistake is the one worth avoiding.
These checks defeat opportunistic forgery and reused photographs. They are not a laboratory examination of security features, and we do not hold a formal anti-spoofing certification — if an auditor requires one by name, we will tell you plainly that we do not have it. What we do have is a documented escalation path and a record of every decision.
Record cross-check
An ID tells you more than whether the face matches
A government ID carries a name, a date of birth and an address. Identity compares those against what you already have on record for that person — and tells you when they stop agreeing.
You keep the details you already legitimately hold for your people: name, date of birth, the address of record, contact numbers. When a verification runs, the data read off the ID is compared against them. Most of the time everything matches and nothing happens. When something does not match, the difference is the signal.
| What disagrees | How Identity treats it |
|---|---|
| Date of birth | High signal. A date of birth does not legitimately change. Flagged for review, not quietly logged. |
| Document number | High signal when a previously seen document changes without a reissue explaining it. |
| Name | Review. Legal name changes are ordinary and common — treated as something to confirm, never as a failure. |
| Address | Informational. People move. Prompts a record update and, where you track approved work locations, a note that one may have changed. |
The comparison happens at the moment of verification. What is kept is the verdict — matched, or did not match, and on which field. The address and date of birth read off the document are used and discarded, so running this check does not turn you into a custodian of government-ID data.
An unexpected address is rarely fraud — it is usually a person who moved and forgot to tell anyone. But a record that quietly drifts out of date is exactly what nobody notices until it matters. This keeps the roster honest as a side effect of a check you were already required to run.
The program engine
The hard part is not the check. It is everything around it.
Any vendor can verify an ID. Keeping a whole roster continuously verified — and proving it years later — is the work.
Defensible randomness
Selection is a recorded draw, so "randomly selected" is reconstructable months later instead of merely asserted.
Clocks that hold
On-demand requests and failure notifications each run their own deadline, visible before they are missed.
Absence handling
Approved leave pauses a check rather than accruing a breach against someone who is not at work.
Chase and escalate
Reminders go out, then escalate to a manager — because the failure mode is not a failed check, it is an ignored one.
Evidence and audit
What gets recorded
Enough to satisfy an auditor. Never more than that.
| Recorded | Why it matters |
|---|---|
| Date and time | Proves the check fell inside the required period |
| Method used | Witnessed session or automated — agreements often treat these differently |
| Outcome | Verified, needs action, declined-with-alternative, or overdue — as distinct states |
| Who performed it | A named human for witnessed sessions; the service and its reference for automated ones |
| Check reference | Ties the verdict to the specific run, so it can be traced without retaining what it examined |
| Consent record | What the individual was told, and what they agreed to, with a version and a timestamp |
Records are retained for the length of the individual's access plus whatever term your obligations specify, and are exportable throughout. An attestation can be produced for any date, not just today.
Privacy by design
We keep the verdict. The face is destroyed.
This is a deliberate architectural decision, not a policy promise — and it is the single most important thing about how Identity is built.
Nothing biometric is kept
Images and any derived face data exist in memory only for the seconds a comparison takes, then are destroyed — not archived, not held by a vendor. What persists is the verdict, the date, and which checks passed.
Notice and consent, recorded
Each individual is told what is collected, why, and for how long, and consents before anything is captured — with the version they saw kept on record.
Yours to run, and yours alone
This is self-service. You configure it, you see the results, and you act on them — JPtheGeek does not run checks on your people or review their outcomes. Identity reports status; it does not fire anyone, and it does not revoke access unless you configure it to.
What Identity is not
The honest boundaries
We would rather you hear this now than discover it during an audit.
- Not a background check. Identity confirms that a person is who they claim to be. It does not screen criminal history, employment or credentials — though it can be pointed at a photo captured during screening for comparison.
- Not device or network monitoring. Where your customer supplies the devices, they normally retain responsibility for monitoring them. Where you supply them, JPtheGeek covers that separately — it is not part of Identity.
- Not access control, by default. Identity knows who is overdue. Whether that suspends access is your policy decision, off unless you turn it on.
- Not legal advice. Your agreement's exact wording governs. We will map the clauses to what Identity does and tell you plainly where a gap remains.
Get started
Send us the requirement.
A regulator, a customer agreement, your own policy — wherever the obligation comes from, we will tell you which parts Identity covers, which it does not, and whether it is worth turning on. You run it from there.