FAQ: Workforce IDV

Persona's Workforce IDV helps organizations verify workers at key points in their lifecycle (candidate screening, onboarding, account recovery, MFA reset, help-desk verification, and step-up before high-risk actions). This prevents unauthorized access to sensitive systems while automating processes to reduce the burden on IT and security teams.

The following FAQs address common questions about Persona's workforce solutions and integrations.

  1. Which Identity and Access Management (IAM) platforms does Persona integrate with?

    Persona has native integrations with:

    Through Persona Authentications — our standards-based OpenID Connect (OIDC) identity provider — Persona can also act as an identity-verification authenticator for any IAM that supports an external OIDC IdP, including Ping and Auth0.

    We're actively developing additional IAM integrations based on customer needs. If you're interested in any of our current native integrations or would like to request integration with a platform not listed here, please contact your Account Team.

  2. Which Human Resources (HRIS/HCM) and Applicant Tracking (ATS) systems does Persona integrate with?

    For employee (post-hire) verification, Persona integrates with your HR system of record to prefill and match against trusted worker data:

    For candidate (pre-hire) verification, Persona integrates with leading ATS platforms to trigger identity verification at the right stage of your hiring funnel:

    We also support API-based custom integrations with any HRIS/HCM/ATS system. If you're interested in our current native integrations or would like to request integration with a platform not listed here, please contact your Account Team.

  3. Which IT service management (ITSM) / help-desk systems does Persona integrate with?

    Persona integrates with ServiceNow so that identity events in Persona (for example, a verification result or a flagged session) can automatically open or update ServiceNow cases — closing the loop for help-desk and IT teams. See ServiceNow integration overview.

  4. How does Persona's Okta integration work?

    The Okta integration allows Persona's identity verification to be triggered directly through Okta's authentication and account-management policies. The flow works as follows:

    • Okta administrators configure identity verification through the Okta Dashboard
    • When triggered (for example, a password reset, MFA change, or sign-in to a sensitive application), workers are redirected to Persona for identity verification
    • Workers complete verification (Government ID + Selfie, etc.)
    • Results are sent back to Okta to authorize the appropriate access

    Persona supports Okta both as Okta's native "Persona IDV" account-management action and as a standards-based OIDC IdP for application sign-in policies. See Triggering Persona IDV within Okta, Configuring Okta via OIDC, and Using Persona Workflows to manage Okta users & profiles for more information.

  5. How does Persona's Cisco Duo integration work?

    Persona's integration with Cisco Duo allows Persona's identity verification to be triggered by Duo administrators. The flow works as follows:

    • Duo help-desk staff trigger identity verification from their console when needed
    • Workers receive a time-limited verification code
    • After entering the code, workers complete Government ID and Selfie verification through Persona (Persona can handle attribute comparison)
    • Results are sent back to Duo, allowing admins to proceed with account actions

    See Cisco Duo integration overview for more information.

  6. How does Persona's Microsoft Entra ID integration work?

    Persona's integration with Microsoft Entra ID lets organizations enable secure self-service password resets, MFA resets, and Temporary Access Pass (TAP) issuance for their workers. The integration leverages Microsoft's Graph API. The flow works as follows:

    • Organizations surface Persona's flow to workers in different ways (e.g. automatically from an internal support/help site, or manually created by help-desk staff)
    • This triggers the employee to receive a Persona verification link
    • The worker verifies their identity using Government ID and Selfie verification (Persona can also handle attribute comparison)
    • After successful verification, the worker can set a temporary password, receive one generated by Entra, or be issued a Temporary Access Pass
    • The worker then signs in to Entra ID

    See Microsoft Entra integration overview and Configuring the Microsoft Entra ID integration in Persona for more information. Persona can also issue a Microsoft Entra Verified ID credential after verification.

  7. How does Persona's OneLogin integration work?

    Persona integrates with OneLogin through Persona Authentications, our OpenID Connect (OIDC) identity provider. OneLogin calls Persona as an OIDC authenticator during authentication flows; Persona can also look up the worker's OneLogin profile via the OneLogin REST API for attribute comparison. See OneLogin integration overview for more information.

  8. How does Persona's Workday integration work?

    Persona offers two Workday integrations:

    • Workday HCM (employee verification): Persona retrieves worker data—including name, date of birth, email, job title, hire date, and other information—from Workday's Get Worker endpoint. During verification, Persona compares Government ID details against this trusted Workday data. See Workday HCM integration overview.
    • Workday Recruiting (candidate verification): Persona automatically sends identity-verification links to candidates based on events in your Workday hiring funnel, without a recruiter manually initiating each one. See Workday Recruiting integration overview.
  9. How do Persona's candidate (ATS) integrations work?

    For pre-hire candidate verification, Persona connects to your ATS to trigger identity verification at the right stage of the hiring funnel (for example, at the offer stage), enrich Persona with candidate/application context, and write verification results back into the ATS record. See the Ashby, Greenhouse, and Fountain integration overviews for the specific trigger and write-back behavior of each platform.

  10. What are Persona's recommended verification methods for Workforce IDV?

    For most workforce use cases, we recommend:

  11. How does Persona handle worker/employee data privacy, especially in regions with strict regulations?

    Persona provides several mechanisms to ensure compliance with strict privacy regulations:

    • Configurable redaction and data retention policies
    • Region-specific consent flows
    • Option to store only verification results without raw PII
    • Support for GDPR right to be forgotten and data access requirements
    • Option to encrypt sensitive data fields

    See Security and Privacy Overview for more detail.

  12. Can Persona do attribute comparison of verification data against our existing worker/employee records?

    Yes, Persona can compare verification data against your existing worker records and match on multiple attributes. We recommend matching against legal name and date of birth for higher assurance. Worker records can be imported from your IAM, HRIS, or ATS system through native integrations, API connections, or pre-fill options.

  13. What happens if a worker / employee fails verification?

    Persona's UI offers automatic retry logic, real-time user guidance, and clear error messages to minimize false failures. When an employee or worker exhausts all retry attempts and reaches a failure screen, you can configure various next steps, including:

    • Automatic step-up verifications
    • Notifications to IT or other internal teams
    • Custom workflows to trigger manual review processes within Persona (via Cases) or in external systems
  14. My organization currently uses Persona for user / customer verification. Do we need to create a separate Persona Org for Workforce IDV?

    Yes, if you currently use Persona for customer/user verification, you will need to create a new Persona Org for your Workforce use case. It is crucial to separate customer data from employee/candidate data for security, governance, and access control—a separate environment alone is not sufficient.

    • Data Security & Governance: Separating customer verification data from worker/employee verification data follows security best practices and maintains clear data boundaries
    • Access Control: A dedicated org allows you to manage permissions specifically for those handling worker/employee data, limiting unnecessary access
    • Reporting & Analytics: Separate orgs provide cleaner reporting and analytics specific to each use case
  15. My organization is interested in using Persona for both Pre-Hire / candidate verification and Post-Hire worker/employee verification. Can these two use cases share the same Persona Org?

    Yes, these two use cases can share the same Persona Org. A separate Persona Org is only required when you need to separate candidate/employee data from customer/user data.

  16. I'm an existing Persona customer. Do I need a separate Order Form for my Workforce use case?

    Yes, if you currently use Persona for customer/user verification, you'll need a separate order form for your workforce use case. This separation is necessary because different use cases have distinct compliance and legal requirements. Additionally, Post-Hire workforce use cases operate under a different pricing structure.

  17. If I'm using Persona for both Pre-Hire and Post-Hire Workforce use cases, can these be on the same order form?

    Yes, these two use cases can share the same order form. The document will outline separate pricing structures for pre-hire and post-hire verifications.

Drafted via Oracle by justin.sayarath@withpersona.com on 2026-06-03T01:30:23.853Z.