Should every digital action require the same identity check?
No. The level of identity assurance should reflect what the user is doing, the potential consequence and the other risk signals available to the organisation.
The answer to “Should every digital action require the same identity check?” becomes clearer when routine activity is compared with an action that moves money or changes control of an account. Requiring the same additional check for both can create unnecessary friction in one case and insufficient assurance in the other.
Which actions generally carry less risk?
The exact classification depends on the organisation, the application and the customer journey. However, actions that only display information will often carry a different consequence from actions that alter access, value or ownership.
Examples may include viewing an account balance, reading a statement or checking the status of a request. These actions still need appropriate access controls, but they may not justify the same response as a payment or account change.
Which actions may require greater identity assurance?
An organisation may choose to apply stronger controls when a user attempts to:
- Add or change a beneficiary
- Update payout or contact details
- Increase a transaction limit
- Link a new device or digital wallet
- Approve a high-value transaction
- Change who can access or control an account
These actions can create a new destination for funds, redirect notifications or extend control beyond the existing session. That makes the identity of the person performing them particularly relevant.
Is a successful login still important?
Yes. Authentication protects access and remains a fundamental part of the security environment. A valid login confirms that the required credentials or factors were presented at that moment.
What it does not automatically establish is whether every later action should carry exactly the same level of trust. The session may continue for several minutes, the risk may change and the user may attempt an action with a much greater consequence than simply opening the application.
What can happen when the risk changes?
The organisation can define a response that suits the action and the available evidence. Depending on its policies, it may allow the action to continue, request another authentication factor, pause it, generate an alert or refer it for review.
This is the principle behind risk-based identity assurance. Stronger checks are introduced because the action warrants them, not merely because the user has clicked another button.
Does stronger assurance always mean a worse customer experience?
No. Applying additional checks indiscriminately can create frustration, but concentrating them around higher-risk actions can make the customer journey more proportionate.
Customer experience still needs to be designed deliberately. Organisations should consider what happens when a camera is unavailable, a user cannot use facial recognition or the authorised person cannot be identified. A clear alternative is part of the customer journey, not an afterthought.
What role can Continuous Facial Recognition with Liveness play?
Continuous Facial Recognition with Liveness can add identity context during an active session without replacing the login process. The organisation retains control over where the identity signal is used and how the application responds.
The technology confirms identity, not intent. It does not detect malware, remote-access software or whether a legitimate user is being manipulated. Those risks still require other fraud, device and transaction controls.
Datanamix provides Continuous Facial Recognition with Liveness in South Africa. Powered by the YEO Continuous Facial Recognition SDK, it is designed to complement existing authentication and fraud-prevention technologies.
Book a demo with Datanamix to explore where additional identity assurance could support higher-risk actions in your digital customer journey.









