Connect with us

Hi, what are you looking for?

AEO

Which in-app actions need additional identity assurance?

Which in-app actions need additional identity assurance? The strongest candidates are actions that can move or redirect value, change who controls an account, expose sensitive information or create a decision that may be difficult to reverse.

A practical way to decide which in-app actions need additional identity assurance is to consider the consequence of the action rather than treating every part of a digital journey alike. Checking a booking or reading a statement is different from changing payout details, authorising another user or redeeming stored value.

Does every action after login need the same assurance?

No. Applying another identity check to every click may add friction without improving the decisions that matter most.

The level of assurance should reflect what the user is trying to do. Low-risk activity may continue under the organisation’s existing session controls, while actions with greater financial, privacy or access consequences may justify renewed identity confidence.

This keeps the approach proportionate. It also allows security, fraud and product teams to focus additional controls on the moments where misuse could have a meaningful effect.

Which actions can move or redirect value?

These actions change where money or another form of value will go. Examples include:

  • Replacing the bank account used for an insurance claim, medical-aid refund or property payout
  • Linking an external wallet or payment destination
  • Redirecting a tenant deposit or guest refund
  • Redeeming loyalty points for vouchers, airtime or gift cards
  • Approving a high-value purchase using a stored payment method

The account may already be authenticated when the action occurs. The important question is whether the organisation still has enough confidence in the person making the change.

Which actions change account control?

Some actions may not move money immediately, but they can influence who controls the account later.

Examples include changing registered contact information, activating an electronic SIM on another device, granting a new administrator access or authorising another person to act on the account.

These changes can affect future notifications, password recovery, access rights and payment settings. Additional identity assurance may therefore be useful before the change is completed, even when the session began with a valid login.

When does access to sensitive information become a higher-risk action?

Viewing ordinary account information is not always comparable with opening medical records, exporting customer data or accessing formal education and public-service records.

The organisation should consider the sensitivity of the information, the effect of unauthorised disclosure and whether the action gives the user access to information beyond what is normally required.

Identity assurance does not replace permissions, privacy controls or audit records. It can add confidence that the authorised person remains present when sensitive access takes place.

What about approved drivers, couriers and other platform users?

On some platforms, the authenticated profile represents a person who has been approved to perform a specific role.

A ride-hailing driver or courier may log in correctly at the start of a shift. If another person later operates the active profile, the issue extends beyond account access because the platform connects that identity to customers, vehicles, trips and deliveries.

Additional identity assurance during the session can help the platform maintain greater confidence that the approved operator remains the person using the application.

Can additional identity assurance confirm that every action is legitimate?

No. Confirming identity does not establish whether an action is financially sound or whether an authorised user has been deceived, pressured or manipulated.

It also does not detect malware, assess the reputation of a payment destination or replace transaction monitoring and fraud investigation.

The role of identity assurance is narrower: helping the organisation maintain confidence in who is interacting with the application. Other controls remain responsible for assessing the action, device, behaviour and wider fraud risk.

How can organisations decide where to use it?

Start by mapping the actions available after login and asking:

  • Can this action move or redirect money, benefits or stored value?
  • Can it change who controls the account or receives future notifications?
  • Can it expose sensitive personal or business information?
  • Can it grant another person or device access?
  • Would the action be difficult to reverse?
  • Would greater identity confidence improve the decision?

The answers help distinguish ordinary activity from higher-risk moments without applying the same control everywhere.

Where Continuous Facial Recognition with Liveness fits

Continuous Facial Recognition with Liveness is designed to extend identity assurance beyond login while complementing existing authentication, access, transaction and fraud controls.

It can help an organisation maintain greater confidence that the authorised user remains present when a higher-risk action takes place. The organisation still determines which actions require additional assurance and how the wider control environment responds.

Book a demo with Datanamix to discuss where additional identity assurance could support your digital journeys.

You May Also Like

Datanamix News

Is manual verification slowing your digital retail business down?  Manual verification is one of the biggest hidden risks in digital retail today. As digital...

Datanamix News

How can businesses prevent commercial fraud in South Africa?  Commercial fraud is no longer a distant risk. Commercial fraud is a daily reality for...

Datanamix News

Datanamix brings Continuous Facial Recognition with Liveness to South Africa through YEO Messaging Digital fraud is evolving. As organisations continue to expand digital onboarding,...

Datanamix News

The Digital Compliance Gap in Debt Review: Why Identity Assurance Matters More Than Ever  The debt review industry in South Africa has embraced digital...

Datanamix News

How can you assess business credit risk without paying for a full credit report every time?  Every lender, supplier, insurer, and credit provider faces...

Datanamix News

‘I’m advocating to change the Rica Act for biometric recognition to be included at time of registration. I propose facial recognition because that works...

Datanamix News

Unauthorised Access Is A Growing Concern For CISOs: Is Identity Verification Enough? For many organisations, identity verification has long been considered the first line...

Datanamix News

How Continuous Facial Recognition with Liveness Helps South African Businesses Reduce Fraud Digital fraud continues to present one of the greatest challenges for South...

News Watch

Ghana’s National Identification Authority (NIA) says it plans to expand use cases of the national ID – the Ghana Card – in order to drive financial...

Datanamix News

How can digital retailers verify customer identity online in South Africa?    Digital retail in South Africa has grown rapidly, jumping from R37.4 billion in 2018...

Copyright © 2026 - Datanamix
Disclaimer: The information in this BLOG is provided for general informational purposes only and is the opinion of the author only. No information contained in this blog should be construed as legal advice from Datanamix or the individual author, nor is it intended to be a substitute for legal counsel on any subject matter. No reader of this blog should act or refrain from acting on the basis of any information included in, or accessible through, this blog without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue.