Watchlists
Watchlists are the galleries that face duplicity check and document duplicity check search against. Each tenant (in case of SaaS) has its own isolated watchlists; the face of a new applicant — and their document name data — is compared against them to decide whether the person is new, returning, blocked, or already being processed.
The watchlists
| Watchlist | Who is in it | Effect of a match |
|---|---|---|
| Customer | Active, verified customers. | Recognized as a returning customer — the attempt can be merged or updated instead of creating a duplicate. |
| Blocklist | People to refuse — known fraudsters or otherwise unwanted. | The onboarding attempt is automatically rejected. |
| Review | Applicants whose verification an operator still has to decide. | The new attempt is flagged as review so it is judged together with the pending case. |
| In-progress (concurrent) | Applicants whose verification is running right now. Internal, transient, not visible to the Company. | Flags a second simultaneous attempt by the same person as concurrent. |
Membership rules
- A person is represented by one watchlist member, tied to their Customer record.
- A member is in at most one of the Customer, Blocklist and Review watchlists at a time — a person is a customer, or blocked, or pending, never two at once.
- The watchlist of a member follows the state of the Customer: activating, blocking, or anonymizing a Customer moves or removes their member accordingly.
- The face gallery and the name gallery are kept in step: whatever moves a face member moves the corresponding name-vector member.
How outcomes move members
Workflow outcomes and operator actions move members between watchlists:
| Action | Effect |
|---|---|
| Onboarding accepted as a new, unique customer | Member added to the Customer watchlist. |
| Onboarding rejected as fraud / operator blocks the person | Member added to the Blocklist. |
| Attempt held for manual review | Member added to the Review watchlist until an operator decides. |
| Verification finishes (any outcome) | The transient In-progress entry is removed. |
| Customer anonymized | Member removed entirely. |
Underlying data
Watchlists do not store photos or readable names. The face galleries hold biometric templates; the name galleries hold non-reversible name vectors (see document duplicity check). The original images and data are retained separately (on the Stored tier) so that templates can be regenerated without asking users to re-enrol.
See also
- Face Duplicity check (1:N)
- Digital Identity Lifecycle — Customer states
- Manual Review