Configure Workflows

The Unifyia platform's workflow module allows administrators to configure workflows for identity issuance, both for platform users and integrated external credential management systems. This tutorial provides an overview on the importance of workflows, supported identity devices, supported identity types and the workflow features.

Overview

Workflows are essential in optimizing the identity issuance process within an organization. Workflows establish a structured framework for identity issuance by defining the steps, required data, and task sequence. This guarantees a consistent and standardized approach to identity issuance.

Customization is a key feature of workflows, allowing tailoring to the specific needs and policies of the organization. You can design various authentication workflows to accommodate different assurance levels. You have the flexibility to configure workflows by selecting essential data elements and ensuring compliance with organizational regulations for data capture.

Furthermore, workflows facilitate users to be associated with group(s), role(s), device profiles, visual IDs, enrollment data, type of identity to be issued, and the sequence of issuance during the identity issuance process. This ensures that each user is issued identities according to their role and requirements.

In addition to allowing creating workflows for the platform users, the Unifyia platform allows organizations to create workflows for external credential manangement systems when integrated to issue and manage PIV IDs.

Compliance with regulatory standards and organizational policies is another crucial aspect facilitated by workflows. Incorporating essential checks and validations ensures adherence to regulatory guidelines and internal policies throughout the identity issuance process. Additionally, workflows offer real-time visibility into the status of identity issuance tasks, empowering administrators to monitor progress effectively.

Supported Identity Devices

  • Personal Identity Verification (PIV) based smart devices
    • ID-One PIV v2.4.1 on Cosmo V8.1
    • ID-One PIV v2.4.2 on Cosmo V8.2
    • ID-One PIV v2.3.4 on Cosmo V7
    • G&D SCE 7.0 with PIV Applet V1.0
    • Thales IDPrime PIV v3.0
    • ZTPass on NXP P71D600
    • Yubico - YubiKey 5 Series
    • Yubico - YubiKey 4 Series
    • Arculus AuthentiKey
    • Swissbit - Swissbit iShield Key
  • Mobile Identities (Requires Unifyia ID Wallet App)

Identity Types

You can configure workflows for the below-listed identity types.

  • PIV (PIV-enabled smart cards/security keys)
  • PIV-I (PIV-enabled smart cards/security keys)
  • CIV (CIV-enabled smart cards/security keys)
  • Derived PIV or DPIV (PIV-enabled smart cards/security keys)
  • Derived FIDO2 or DFIDO2 (FIDO2-enabled smart cards/security keys)
  • FIDO2 passkeys (FIDO2-enabled smart cards/security keys)
  • Mobile Identities (Mobile IDs), Derived Mobile Identities (DMobile IDs) using the Unifyia ID Wallet app

You can configure a single workflow that enables users to be issued single or multiple types of credentials that can be used for multi-factor authentication. The possible combinations are listed below. It may be noted that a PIV ID must be issued first for a user to enable the issuance of DPIV, DFIDO, and DMobile identitites.

  1. PIV ID
  2. PIV-I ID
  3. CIV ID
  4. FIDO2 passkeys
  5. Mobile Identities
  6. PIV ID + FIDO2 passkeys
  7. PIV ID + FIDO2 passkeys, Mobile Identities
  8. FIDO2 passkeys, Mobile Identities
  9. DPIV (Derived PIV)
  10. DFIDO2 (Derived FIDO2)
  11. DMobile ID (Derived Mobile ID)
  12. DPIV + DFIDO2
  13. DPIV + DMobile ID
  14. DFIDO2 + DMobile ID
  15. DPIV + DFIDO2 + DMobile Identities

The workflow feature of the Unifyia platform allows you to do the following:

  1. Create a workflow for the Unifyia platform users
  2. Create a workflow for the integrated external credential management systems (External CMS) for PIV ID issuance
  3. Search a workflow
  4. Edit a workflow
  5. Clone a workflow
  6. Delete a workflow