Customer Identity

Every extra step costs you customers. Every missing one costs you more.

Customer identity is the only part of IAM where the security team and the growth team are measured on the same screen, in opposite directions. The registration flow is both a funnel and a control.

Two teams, one screen, opposite directions

Both are right. That is what makes this hard, and why the answer is never simply "less friction" or "more checks".

Growth is measured on
  • Registrations completed, not started
  • Return visits that did not need a reset
  • Checkouts that finished
  • Markets entered on schedule
Risk is measured on
  • Account takeovers that did not happen
  • Fraudulent transactions blocked
  • Consent that can be evidenced
  • Regulators who stayed quiet

The reconciliation is not a compromise between the two. It is spending friction precisely, at the moments where something is actually at stake.

The journey

Where the friction belongs

Five moments, one customer. Most programmes apply the same authentication to all of them, which means the first three are too heavy and the last one is too light.

01

Discover

Browsing, reading, comparing. No account, no claim, nothing at stake.

02

Register

The first commitment. Ask for the minimum that lets the next thing happen.

03

Verify

Establishing that the person is who they say — documents, credentials, checks.

04

Return

Signing back in, on a device that has probably been seen before.

05

Transact

Moving money, changing an address, granting somebody else access.

What the journey has to carry

More than authentication. Most of what decides success happens around it.

Registration that asks for little

Progressive profiling: collect what the first interaction needs, and the rest later, when the person has a reason to give it.

Verification when it matters

Document checks, KYC and AML services invoked at the point in the journey where the risk appears — not on every user because it was easier to configure.

Consent as a first-class object

Captured, recorded, revocable and auditable per purpose. Privacy regimes differ by market, and the difference belongs in the flow rather than the code.

The identities they already have

Social and federated login, and increasingly credentials from a wallet the person controls, so account creation is not a wall in front of the product.

Passwordless where it helps conversion

Passkeys remove both the friction of remembering and the cost of resetting. For consumer populations the operational saving is often the easier business case.

Fraud signals in the decision

Device, behaviour and reputation feeding the same policy that decides whether this registration or this transaction earns an extra step.

How Monokee approaches it

One journey, many providers, no redeployment

The providers become nodes

Verification services, antifraud engines, risk scoring and MFA providers land on the canvas as steps. Your application talks to one endpoint and never learns which vendor is behind it.

Swap without a release

Replacing a verification provider or adding a market-specific consent step is an edit to a flow. The applications keep running, because they were never holding the logic.

Assurance bound to the action

A flow is attached to an application, an API or a single transaction, so a high-value operation can demand a fresh factor while browsing stays invisible.

Bring us the step where customers drop out

We'll model the journey around it and show you what moving that step actually takes.

Talk to an expert