What is continuous identity assurance?
It is the practice of maintaining confidence in who is using a digital application after the initial login. Unlike point-in-time authentication, it considers whether the person interacting with the application remains the authorised user as the session continues.
The question “What is continuous identity assurance?” becomes clearer when access and later activity are treated as different moments. Authentication helps establish whether the correct credentials or factors were presented at a particular time. Identity assurance during the session helps an organisation assess whether later activity should still be trusted as belonging to the same person. It does not make login security unnecessary.
Identity checks serve different purposes
Digital identity is not established through one control alone. Different checks support different stages of the customer journey:
- Identity verification helps establish that a person is who they claim to be, often during onboarding or account recovery.
- Authentication checks whether the person attempting to access an account can present the required credentials or factors.
- Session-level identity assurance adds context after access has been granted.
- Transaction controls help an organisation decide whether a particular action should proceed, require another check or be reviewed.
These controls are related, but they are not interchangeable. A successful login confirms that the required checks were passed at that point. It does not, by itself, answer every identity question that may arise later in the session.
Why the action matters as much as the access
The risk within an application is not constant. Viewing an account balance is different from adding a beneficiary, changing payout details or approving a high-value payment. Updating an email address is different from reading a notification.
This is why identity assurance can be applied according to the significance of the action. An organisation may decide that ordinary activity can continue under its existing controls, while selected higher-risk actions require greater confidence in who is present.
The aim is not to treat every click as suspicious. It is to identify the moments where a change in control, destination or value creates a stronger need for identity context.
What can support identity assurance during a session?
Organisations can draw on more than one type of signal. Depending on the application and its risk model, these may include device information, behavioural patterns, transaction risk, session context and biometric presence.
An identity signal can help answer a narrow question: does the application still have reason to believe that the authorised person is present? The signal does not make the business decision on its own. It becomes one input into the organisation’s existing session, fraud and authentication policies.
That distinction matters. The application must still determine what happens when confidence changes. It may continue the session, request another form of authentication, pause a sensitive action, refer the event for review or take another response defined by the organisation.
What continuous identity assurance does not prove
Confirming identity is not the same as confirming intent.
A recognised user may still have been deceived into making a payment. They may be acting under pressure, or their device may be affected by malicious or remote-access software. A facial identity signal does not identify malware and cannot determine whether a person’s decision is informed or voluntary.
Continuous identity assurance should therefore be treated as one layer within a broader control environment. It can add identity context, but it does not replace multi-factor authentication, device security, transaction monitoring, behavioural analytics, customer education or human review.
What responsible implementation requires
Before adding another identity signal, an organisation should define the problem it expects that signal to address. It should also establish:
- Which actions justify additional identity assurance
- What information the technology captures, stores or transmits
- How the application responds when the authorised person cannot be identified
- What alternative is available when facial recognition cannot be used
- How consent, transparency, retention and access will be handled
- How the control will work alongside existing authentication and fraud systems
These decisions are as important as the technology. They determine whether identity assurance supports the customer journey or simply introduces another isolated control.
Where Continuous Facial Recognition with Liveness fits
Continuous Facial Recognition with Liveness is one way to add an identity signal during an active digital session. It is designed to work alongside an application’s existing authentication and session-management infrastructure, while the organisation retains control over how the signal is used and what response should follow.
Datanamix has introduced the technology to South Africa. The solution is powered by the YEO Continuous Facial Recognition SDK and is positioned as an additional identity-assurance layer, not a replacement for the authentication and fraud controls an organisation already uses.
The practical starting point is to identify the actions where knowing who is present would materially improve a decision. Contact Datanamix to discuss where Continuous Facial Recognition with Liveness may fit within your existing digital journey.









