IDFLOW

Insider Threat Protection™

Every authorised action is attributable, auditable and accountable.

The Risk

One of the greatest risks facing organisations is not external hackers but authorised users who intentionally or unintentionally misuse their access.

Unauthorised viewing of confidential information
Downloading sensitive documents
Altering records
Changing banking details
Exporting customer data
Approving fraudulent transactions
Misusing administrator privileges

The IDFlow Approach

Rather than assuming insider threats cannot occur, IDFlow Secure™ is designed to make every authorised action attributable, auditable and accountable.

Hold a fully verified personal IDFlow account
Be linked to the organisation through verified authority
Use Multi-Factor Authentication
Operate within role-based permissions
Be individually accountable for every action performed

Verified User Accountability™

Every action performed within an organisation is linked to:

IDFlow Number™
Verified Identity
Verified Organisation
Verified Role
Verified Device
Session Information

Users cannot act anonymously.

Complete Audit Trail™

Every significant action records:

Who performed itWhich organisation it relates toDate and timeDevice usedIP address (where permitted)Previous valueNew valueApproval chain (if applicable)Authentication method used

The audit history is tamper-evident and retained according to organisational policy and applicable law.

User Activity History™

Every verified member maintains a secure activity history. Examples include:

Administrator created
Director approved
Payroll changed
Banking details updated
Document accessed
Document shared
Permission granted
API created
Meeting joined
Identity verified
Payment approved

Users can view their own activity history. Organisations can review activity for users they administer, subject to permissions and applicable privacy laws.

Audit Requests™

Authorised organisations may request a detailed audit of significant events. The audit report can include:

User identity
Verified role
Timeline of actions
Documents accessed
Approvals given
Authentication events
Device history
Linked audit references

Audit access must itself be permission-controlled and fully logged.

Role-Based Access Control™

Every employee only receives access required for their role. Least-privilege access reduces the impact of insider misuse.

Payroll Administrator

Payroll
Medical Records

HR Manager

Employee Files
Banking Administration

Finance Manager

Payments
Recruitment Interviews

High-Risk Actions

Critical actions require additional safeguards, such as Multi-Party Trust Approval™, re-authentication, multi-factor authentication, and executive approval where configured.

Banking changesAPI creationDirector changesLarge paymentsSuper Administrator changes

Trust Principle

IDFlow Secure™ does not assume that trusted people cannot become insider threats. Instead, it creates an environment where every significant action is attributable to a verified identity, protected by layered security controls, and supported by comprehensive audit records.

This greatly improves accountability and supports organisations in investigating suspected misuse while respecting privacy and legal requirements.

Verified People. Verified Actions. Verified Accountability.

Verify Once. Use Everywhere.™