Nothing to reset
Removing passwords removes password resets, expiry policies and rotation schedules. Device recovery and other support needs remain.
Provision employees from existing HR photos, enroll their phones and use face-based sign-in over OIDC or SAML. Remove the password path while keeping a defined recovery process.
Workforce identity programs fail on the rollout that never finishes, the resets that never stop, and the shared workstations nobody designed for. The password has a running cost and every organization pays it. Gartner has attributed as much as 20 to 50 percent of help desk volume to password resets, and Forrester has put a single assisted reset at roughly 70 dollars once labor and lost productivity are counted. That is an operating tax on the credential that also happens to be your largest attack surface.
The queue is worse than expensive. It is a documented way in: in 2023 attackers impersonated an employee to the MGM Resorts IT help desk in a single phone call, and the company reported an impact of roughly 100 million dollars. You cannot train your way out of a process whose entire purpose is to help a stranger who says they are locked out.
Removing passwords removes password resets, expiry policies and rotation schedules. Device recovery and other support needs remain.
A recovery call alone cannot satisfy the configured face ceremony. Binding a new phone needs the one-time PIN in the employee’s own mailbox, plus SMS when a mobile number is on file, proof of the new device key, and then a face check against the original enrollment reference. Missing access to the verified mailbox or reference requires administrator recovery.
Removing passwords also removes the need to manage password quality and rotation.
Enrollment can delay passwordless rollouts. SenseCrypt can mint face tokens in bulk from existing HR photos; employees then bind their phones before using phone-based sign-in.
Staff without a usable photo can self-enroll under an email-domain allow-list and use the same lifecycle, groups and roles as imported users.
Photo provisioning needs no user action or enrollment fair. Coverage starts with the import; employees still bind their phone before using the phone sign-in methods.
Each photo is forwarded in memory to a firewalled minting service and dropped the moment the token is minted. It touches no disk, no database and no log, and what remains is a sealed token designed to prevent reconstruction of the face.
The employee installs the companion app and binds it once with a one-time PIN sent to their mailbox. After that the ceremony is a glance, and a PIN is needed again only when binding or replacing a device.
Clinics, plants, depots and registers run on machines that belong to nobody. That is precisely where device-bound credentials fall apart, because the credential lives on the wrong device, and the workaround ends up being a shared password taped under the counter.
The workstation displays a code. The worker's enrolled phone performs the cryptographic and face checks, linking the resulting sign-in to that person.
No face enrollment or installed agent is required on a supported workstation. It can show the sign-in code, while browser sessions and application data remain subject to your workstation policy.
The terminal can serve each shift while sessions are ended between users and each sign-in is verified and logged against one individual. Accountability stays personal even when the hardware is not.
A desk browser, a kiosk and a mobile web page all run the same flow, because none of them need to know anything about the employee in front of them.
SenseCrypt fronts your applications as an ordinary standards-based identity provider, so the integration is work your team already knows and nothing about your app estate has to change shape. Photo provisioning can start before user action, but phone enrollment and application validation still matter. Schedule legacy sign-in retirement once the pilot, device coverage and recovery policy are ready.
SenseCrypt issues roles and permissions in tokens or assertions; your application enforces them. SenseCrypt enforces its own default-closed sign-in group gate and admin-console capability checks.
Provision through SCIM 2.0 from your existing directory. Keep the source of truth and lifecycle ownership in one place.
The departure path is the part worth reading twice, because it fails closed rather than fading out.
A user provisioned ahead of their photo is a pending shell that activates at the first ceremony, so onboarding is not blocked waiting for an HR image to arrive.
Replacing the photo mints a new token only when it is biometrically the same person. A swapped image does not quietly become a new way in.
Deprovisioning cuts the person’s device keys and refresh-token families in one step. Suspension is enforced by the IdP on subsequent protected checks and token refresh. Applications must separately end their existing sessions and enforce token expiry.
For sensitive operations such as production changes or payment runs, request a fresh face check through CIBA. FAPI-CIBA is supported for financial-grade flows. Your application must validate the response and enforce the requested action.
The request starts a device-bound live face check. Tapping a prompt or holding the phone alone does not complete that check.
Verify the fields carried in the signed payload. FAPI 2.0 Message Signing and FAPI-CIBA support financial-grade flows, but your application must still validate the named operation and enforce its authorization.
The calling system receives a pass or a fail it can verify, not a code somebody read aloud on a call.
Export person-level verification events as CSV. Console changes are recorded in a separate tamper-evident chain. Your application must log its own access decisions.