VettiGuard

Role-aware handbook

VettiGuard user guide

What each module is for, when it should be used, and the safe sequence for completing its main tasks.

Create account
Page 1 of 36
Welcome01 / 36
VG

Workspace handbook · 2026.08.82

VettiGuard user guide

What this is for

A practical introduction to the everyday VettiGuard workspace modules used to protect web, API, and mobile experiences.

When to use it

Use this guide during onboarding, when configuring a new integration, or whenever a module’s purpose and operating sequence are unclear.

How to use it

  1. Open the contents panel to jump directly to a module.
  2. Use the Previous and Next controls, arrow keys, or a horizontal swipe to turn pages.
  3. Select “Open module” from a chapter when you are ready to perform the task.
  4. Print or save as PDF from your browser for a conventional paginated copy.
VettiGuard user guideVettiGuard user guide
Start here02 / 36

How the workspace fits together

What this is for

VettiGuard separates application registration, verification policy, operational review, and account governance so each activity can be controlled independently.

When to use it

Read this page before your first implementation or when planning who should receive each workspace permission.

How to use it

  1. Register a protected site or mobile application.
  2. Issue a scoped API credential and keep private secrets on your server only.
  3. Choose a Trust Journey or configure the required verification controls.
  4. Integrate the browser, server, Android, or iOS SDK.
  5. Verify every response on your backend before allowing the protected action.
  6. Use logs, monitoring, reviews, and threat intelligence to operate the integration safely.
VettiGuard user guideHow the workspace fits together
Using the interface03 / 36

Colour theme and accessible display

What this is for

VettiGuard supports light and dark presentation while keeping controls, documentation, tables, alerts, and protected-site previews readable and keyboard accessible.

When to use it

Use these controls when the current display is uncomfortable, when your operating system changes theme, or when checking a branded integration before launch.

How to use it

  1. Use the sun or moon control in the top bar to switch theme.
  2. Your explicit choice is saved on the current browser. Without a saved choice, VettiGuard follows the operating-system theme.
  3. Use Tab and Shift+Tab to move through controls; the focused control receives a visible outline.
  4. Increase browser zoom when needed. Responsive layouts, filters, tables, dialogs, and guide pages reflow for smaller screens.
  5. On phones, data tables are presented as labelled record cards where possible; horizontally dense directory tables remain swipe-scrollable.
  6. Review governed widget previews in both themes before publishing a site-specific colour; the CAPTCHA chrome remains merchant-neutral and shows only VettiGuard attribution.
VettiGuard user guideColour theme and accessible display
Workspace04 / 36

Dashboard

What this is for

A concise overview of verification activity, configuration readiness, usage, and items that need attention.

When to use it

Use it at the start of a work session or after a deployment to identify the next operational action.

How to use it

  1. Review readiness and usage cards.
  2. Open warnings or incomplete setup items.
  3. Follow links into the relevant module.
  4. Confirm activity returns to normal after changes.
Open module
VettiGuard user guideDashboard
Workspace05 / 36

Analytics & reports

What this is for

A privacy-safe reporting workspace for verification, API, webhook, identity, and threat performance.

When to use it

Use it for operational reviews, customer reporting, integration optimisation, and recurring management summaries.

How to use it

  1. Choose a reporting period.
  2. Review the KPI cards and performance indicators.
  3. Export the current snapshot as CSV when detailed analysis is required.
  4. Save a reusable report name and period.
  5. Optionally configure a daily, weekly, or monthly recipient.
Open module
VettiGuard user guideAnalytics & reports
Workspace06 / 36

Getting started

What this is for

A resumable workspace and integration activation centre that connects protected applications, SDK/server traffic, authoritative verification, operational readiness, and Observe-first production launch.

When to use it

Use it when creating a workspace, onboarding a browser/server/mobile integration, preparing a release, or confirming that a production target is genuinely ready.

How to use it

  1. Complete the workspace-level checklist.
  2. Create an integration profile for Browser, Server/API, Native mobile, or Hybrid use and select the exact protected application target.
  3. Install the appropriate SDK or server integration and send safe test traffic; VettiGuard automatically detects successful application activity.
  4. Complete authoritative backend verification where the integration requires it.
  5. Resolve every target-aware required readiness check and save a readiness snapshot.
  6. For a production profile, mark the integration live only after readiness passes; VettiGuard starts it in Observe mode so real traffic can be reviewed before stronger enforcement.
Open module
VettiGuard user guideGetting started
Workspace07 / 36

Notifications

What this is for

A personal, permission-aware activity centre for operational, security, review, identity, billing, account, and product events relevant to your role.

When to use it

Use it to review new activity, open the affected module, archive completed items, and choose whether transactional summaries should also arrive by email.

How to use it

  1. Open the bell in the top bar or Notifications in the sidebar.
  2. Filter by status, category, severity, or keywords.
  3. Open an item to mark it read and continue to the relevant module.
  4. Archive items that no longer need attention.
  5. Set categories, email cadence, timezone, and quiet hours under Delivery preferences.
Open module
VettiGuard user guideNotifications
Trust08 / 36

Trust center

What this is for

Shows the assurance methods available across your sites, mobile apps, journeys, and policies.

When to use it

Use it to assess coverage, identify missing controls, and explain the overall trust posture to stakeholders.

How to use it

  1. Review assurance coverage.
  2. Inspect areas with partial or missing protection.
  3. Open the linked journey, site, or policy.
  4. Recheck coverage after publishing changes.
Open module
VettiGuard user guideTrust center
Trust09 / 36

Trust journeys

What this is for

Builds reusable, server-managed sequences such as human verification, liveness, identity, and device authorisation.

When to use it

Use a journey when one protected action needs several ordered assurance steps or a reusable policy across channels.

How to use it

  1. Select a template or create a journey.
  2. Choose steps, fallbacks, and completion rules.
  3. Submit and approve the version when governance requires it.
  4. Start the journey from your backend.
  5. Verify the final journey response before continuing the action.
Open module
VettiGuard user guideTrust journeys
Trust10 / 36

Trust reviews

What this is for

Queues decisions that need authorised human review instead of an automatic allow or deny outcome.

When to use it

Use it for escalated identity, risk, or sensitive-operation cases requiring evidence and accountability.

How to use it

  1. Filter the review queue.
  2. Open the case and inspect safe evidence.
  3. Assign the case when required.
  4. Record the decision and rationale.
  5. Confirm downstream status is updated.
Open module
VettiGuard user guideTrust reviews
Trust11 / 36

Risk rules

What this is for

Creates explainable conditions that allow, challenge, review, or block an operation based on trusted signals.

When to use it

Use it when different traffic or transaction conditions require different assurance levels.

How to use it

  1. Choose the protected target.
  2. Create ordered rules with narrow conditions.
  3. Use the simulator against representative inputs.
  4. Review and activate the policy.
  5. Monitor decision history and tune carefully.
Open module
VettiGuard user guideRisk rules
Trust12 / 36

Detection intelligence

What this is for

Measures behavioural risk with short-lived privacy-safe device correlation, explainable model versions, and customer outcome feedback.

When to use it

Use it when tuning automated verification, reviewing possible bots, measuring false positives, or preparing a model version for safe activation.

How to use it

  1. Start in Observe only mode and collect a representative sample.
  2. Review priority assessments and the bounded explanation for each score.
  3. Record legitimate, abuse, approved automation, false-positive, or false-negative outcomes.
  4. Create a new model version and run it in Shadow state before activation.
  5. Review precision, recall, false-positive rate, challenge rate, and drift before enabling enforcement.
Open module
VettiGuard user guideDetection intelligence
Trust13 / 36

Account Defence

What this is for

Protects login, signup, password-reset, recovery, and promotion workflows from credential stuffing, account takeover, fake accounts, and multi-account abuse.

When to use it

Use it after server-side verification when an account-sensitive event occurs, especially authentication failures, unfamiliar-device logins, recovery attempts, or promotion redemption.

How to use it

  1. Keep enforcement in Observe only mode while integrating the account assessment endpoint.
  2. Send a stable customer subject ID, a short-lived device ID, the event type, and the outcome from your backend.
  3. Review elevated assessments and their bounded reasons without exposing raw customer identifiers.
  4. Record confirmed takeover, credential stuffing, fake-account, recovery-abuse, legitimate, false-positive, or false-negative outcomes.
  5. Trust a device only after your own strong authentication or MFA succeeds.
  6. Import only SHA-1 hashes of known breached passwords and use the range endpoint so raw passwords and full hashes never leave your application.
  7. Enable step-up mode before considering block enforcement.
Open module
VettiGuard user guideAccount Defence
Trust14 / 36

Fraud Defence

What this is for

Protects payments, transfers, refunds, promotions, OTP delivery, SMS traffic, and email-based workflows from fraud and communications abuse.

When to use it

Use it from your backend before committing a transaction, issuing an OTP, sending a chargeable SMS, accepting a refund, or trusting a new email address.

How to use it

  1. Keep the policy in Observe only mode while sending representative transaction, SMS, and email events.
  2. Use stable internal references for the subject, transaction, device, payment instrument, phone, or email; VettiGuard converts them into workspace-scoped hashes.
  3. Provide high-value, new-payee, country-mismatch, disposable-email, high-cost-destination, and verification indicators only when your system has established them.
  4. Review elevated assessments and record confirmed payment fraud, chargebacks, refund abuse, SMS pumping, OTP abuse, promotion abuse, legitimate activity, false positives, or false negatives.
  5. Maintain a local disposable, blocked, or allowed email-domain list when external email intelligence is not used.
  6. Enable step-up mode before considering block enforcement.
Open module
VettiGuard user guideFraud Defence
Trust15 / 36

Edge Enforcement

What this is for

Applies VettiGuard decisions before sensitive requests reach application code and manages short-lived pre-clearance for recently verified traffic.

When to use it

Use it for checkout, login, recovery, API, and other high-value paths that should be challenged or blocked at a reverse proxy, gateway, worker, or edge runtime.

How to use it

  1. Start in Observe only mode and connect the edge decision endpoint from a trusted server-side adapter.
  2. Create narrow path and action policies for sensitive operations.
  3. After a successful verification, issue a clearance token and bind it to the required hostname, action, path prefix, customer subject, or device.
  4. Set the clearance in a secure first-party cookie or trusted gateway header.
  5. Connect Ozibus with the one-time signing secret so it can request preflight decisions and return delivery, bounce, complaint, cost, latency, and pumping signals.
  6. Review decision and clearance activity before enabling challenge or enforce mode.
Open module
VettiGuard user guideEdge Enforcement
Trust16 / 36

Agent Trust

What this is for

Registers AI agents and approved automation with signed identities, declared purposes, scoped permissions, rate limits, and human approval for sensitive actions.

When to use it

Use it when software agents, assistants, crawlers, or scheduled integrations need controlled access that is more precise and auditable than an ordinary shared API key.

How to use it

  1. Keep the workspace policy in Observe only mode during integration.
  2. Register the agent, select its type and protected site, and document the declared purpose and owner.
  3. Grant the narrowest scopes and action names required.
  4. Add payment, deletion, publication, credential, identity, or other sensitive scopes to the human-approval list.
  5. Copy the one-time signing secret into the agent secret manager.
  6. Sign the exact request body with a timestamp and unique nonce.
  7. Review pending approvals and decision history before enabling restriction or enforcement.
Open module
VettiGuard user guideAgent Trust
Trust17 / 36

Session Integrity

What this is for

Continuously evaluates whether an authenticated session remains consistent with its privacy-safe subject, device, network, country, and authentication context.

When to use it

Use it after login, recovery, or another successful verification to protect account, payment, administration, and other long-lived authenticated workflows from session theft or risky continuity changes.

How to use it

  1. Keep the policy in Observe only mode while integrating.
  2. Call the server-side start endpoint after authentication and store the returned session token only in trusted session storage.
  3. Call the assess endpoint before sensitive actions and when device, network, country, authentication age, or client-integrity context changes.
  4. When the decision is challenge, complete an appropriate VettiGuard step-up and retry with step_up_completed set.
  5. Revoke the VettiGuard session whenever the application session is terminated, credentials change, or compromise is suspected.
  6. Review concentrated challenge and block alerts before enabling enforce mode.
Open module
VettiGuard user guideSession Integrity
Trust18 / 36

API Protection

What this is for

Protects application APIs from abusive velocity, replay, idempotency conflicts, enumeration, scraping, oversized requests, excessive query depth, and high resource cost using privacy-safe bounded metadata.

When to use it

Use it before expensive, sensitive, list, search, export, payment, account, administration, or write operations that need application-aware protection beyond edge rate limiting.

How to use it

  1. Keep the workspace in Observe only mode during integration.
  2. Create endpoint policies for sensitive or expensive route patterns.
  3. Call the server-side assess endpoint before the protected work begins.
  4. Send only bounded measurements and opaque references; never send request bodies, tokens, queries, or personal data.
  5. Honour throttle, challenge, and block decisions only after reviewing observe-mode outcomes.
  6. Submit confirmed abuse and false-positive outcomes through feedback.
  7. Review concentrated abuse, scraping, and replay alerts before enabling enforce mode.
Open module
VettiGuard user guideAPI Protection
Trust19 / 36

Rate Limiting

What this is for

Controls API consumption with distributed token buckets, optional fixed-window quotas, weighted request costs, and privacy-safe hierarchical scopes.

When to use it

Use it when an API, action, subject, device, route, or customer-defined scope needs predictable burst and sustained traffic limits independent of abuse classification.

How to use it

  1. Create policies in Observe mode for representative actions.
  2. Choose capacity and refill rate for burst and sustained throughput.
  3. Add subject, device, route, workspace, application, or custom-scope policies to build a hierarchy.
  4. Optionally add minute, hour, day, or monthly fixed quotas.
  5. Call the atomic check-and-consume endpoint immediately before protected work.
  6. Review simulated outcomes before moving policies to Throttle or Enforce.
  7. Review the backend-readiness banner; use Redis for production scale and choose a deliberate degraded-backend policy.
Open module
VettiGuard user guideRate Limiting
Trust20 / 36

Concurrency Control

What this is for

Protects expensive or scarce workloads by limiting how many operations may be in flight at the same time using expiring distributed leases.

When to use it

Use it for report generation, exports, AI or identity workloads, payment processing, large searches, webhooks, background jobs, or any operation where request rate alone does not prevent resource exhaustion.

How to use it

  1. Start policies in Observe mode and choose the narrowest action and scope.
  2. Set maximum concurrency from real downstream capacity rather than request volume.
  3. Choose a lease TTL long enough for normal work but short enough to recover quickly after crashes.
  4. Acquire a lease immediately before expensive work starts.
  5. If the operation runs longer than the initial TTL, renew the lease before it expires.
  6. Release the lease immediately after success, failure, or cancellation.
  7. Review saturation and retry behaviour before promoting policies to Wait or Enforce.
Open module
VettiGuard user guideConcurrency Control
Trust21 / 36

Dependency Resilience

What this is for

Protects downstream providers and internal dependencies with circuit breakers, bulkhead capacity, retry budgets, half-open probes, and controlled load shedding.

When to use it

Use it when your application depends on payment, messaging, identity, AI, storage, partner, or internal services whose failure or saturation should not cascade through your product.

How to use it

  1. Name the dependency using a stable non-secret key and start its policies in Observe mode.
  2. Set a rolling failure threshold and minimum request sample from real dependency behaviour.
  3. Choose an open duration and a small half-open probe allowance.
  4. Set a retry budget so retries cannot multiply an outage.
  5. Optionally set a bulkhead maximum in-flight value for the dependency.
  6. Call admission immediately before the downstream operation and execute only when allowed.
  7. Report success, failure, timeout, or cancellation with the signed admission token after the attempt completes.
  8. Review simulated opens, shed rates, retry pressure, and probe recovery before enabling enforcement.
Open module
VettiGuard user guideDependency Resilience
Trust22 / 36

Trust Orchestration

What this is for

Combines specialist VettiGuard evidence into one explainable, context-bound allow, challenge, review, or block outcome and can issue a short-lived signed decision receipt for downstream enforcement.

When to use it

Use it at the final decision boundary for sensitive actions that depend on several controls, such as authentication plus session integrity, payment plus fraud defence, or API protection plus identity assurance.

How to use it

  1. Keep orchestration in Observe only mode while integrating.
  2. Create a narrowly scoped candidate action policy with required evidence, assurance, thresholds, and receipt limits.
  3. Replay representative historical decisions through policy simulation.
  4. Review changed decisions, block and challenge rates, missing evidence, and guardrail outcomes.
  5. Run a candidate simulation, review the results, and then promote the candidate through the governed activation flow.
  6. Call the orchestration endpoint from trusted infrastructure, use authoritative VettiGuard assessment UUIDs, and bind the request to an action, subject, resource, application, and context.
  7. Verify and consume the signed receipt immediately before the protected operation.
  8. Submit confirmed abuse, legitimate, false-positive, and false-negative outcomes.
Open module
VettiGuard user guideTrust Orchestration
Trust23 / 36

Threat intelligence

What this is for

Correlates privacy-safe local telemetry into suspected abuse campaigns and governed response indicators.

When to use it

Use it when replay, probing, integrity bypass, or repeated verification failures suggest coordinated abuse.

How to use it

  1. Review active campaigns and risk evidence.
  2. Assign an investigator and add notes.
  3. Apply watch or challenge indicators when justified.
  4. Use temporary blocking only with authorised review.
  5. Resolve or mark false positives to improve operations.
Open module
VettiGuard user guideThreat intelligence
Applications24 / 36

Protected sites

What this is for

Registers browser applications, allowed hostnames, actions, challenge policy, and server-verification credentials.

When to use it

Use it before adding VettiGuard to a website or when changing domains, actions, or production policy.

How to use it

  1. Create the site and choose the environment.
  2. Add exact allowed domains.
  3. Copy the public site key to the browser integration.
  4. Store the private secret only on your backend.
  5. Complete a test verification and then activate production settings.
Open module
VettiGuard user guideProtected sites
Applications25 / 36

Mobile applications

What this is for

Registers Android and iOS applications with package or bundle identity, integrity providers, and mobile credentials.

When to use it

Use it before integrating native VettiGuard APIs or when releasing a new application identity.

How to use it

  1. Create the mobile application.
  2. Add Android package/signing or iOS bundle/team details.
  3. Configure Play Integrity or App Attest.
  4. Store the mobile secret on your backend.
  5. Test nonce, attestation, challenge, and server verification.
Open module
VettiGuard user guideMobile applications
Applications26 / 36

API credentials

What this is for

Issues independently revocable credentials with limited scopes, expiry, environment, and optional network restrictions.

When to use it

Use it for server-to-server integrations, automation, CI, or separating credentials by application and responsibility.

How to use it

  1. Choose the minimum scopes.
  2. Set an expiry and environment.
  3. Copy the secret once into a secret manager.
  4. Monitor last use and network spread.
  5. Rotate before expiry and revoke unused credentials.
Open module
VettiGuard user guideAPI credentials
Verification27 / 36

Visual library

What this is for

Manages accessible image sets used by visual verification challenges.

When to use it

Use it to replace unsuitable imagery, localise a challenge set, or activate a curated set for a protected site.

How to use it

  1. Create or select a challenge set.
  2. Upload clear, rights-safe images.
  3. Add accurate labels and alternatives.
  4. Preview the challenge.
  5. Activate the set only after review.
Open module
VettiGuard user guideVisual library
Verification28 / 36

Facial verification

What this is for

Reviews consent-based liveness sessions, outcomes, fallbacks, and operational status.

When to use it

Use it for supported workflows that require proof of a live person and your policy permits facial processing.

How to use it

  1. Review the session purpose and consent state.
  2. Inspect liveness and quality checks.
  3. Follow configured fallback or review procedures.
  4. Record an operational outcome.
  5. Respect retention and deletion policy.
Open module
VettiGuard user guideFacial verification
Verification29 / 36

Biometric enrollments

What this is for

Shows enrolled biometric identities and device-bound credentials used for later matching or authorisation.

When to use it

Use it to inspect enrollment health or revoke a lost, replaced, or compromised enrollment.

How to use it

  1. Search for the enrollment.
  2. Confirm the subject and device context.
  3. Review status and recent activity.
  4. Revoke only with a documented reason.
  5. Have the user complete a fresh enrollment if needed.
Open module
VettiGuard user guideBiometric enrollments
Verification30 / 36

Identity verification

What this is for

Manages documentary identity cases, applicant capture links, provider checks, evidence, and authorised human decisions.

When to use it

Use it for KYC, onboarding, recovery, or other workflows that genuinely require documentary evidence.

How to use it

  1. Create a case and define required evidence.
  2. Send a secure, expiring applicant capture link.
  3. Review uploaded evidence and extracted data.
  4. Run the configured provider checks.
  5. Make and document the final human decision.
  6. Export a governed evidence bundle only when authorised.
Open module
VettiGuard user guideIdentity verification
Observability31 / 36

API request logs

What this is for

Provides privacy-safe records of API endpoints, outcomes, status codes, and latency.

When to use it

Use it to troubleshoot integration failures, confirm traffic, or investigate unusual response patterns.

How to use it

  1. Filter by endpoint, status, or time.
  2. Locate the request reference.
  3. Compare the safe error code with API documentation.
  4. Correlate with monitoring or application logs.
  5. Correct the integration without exposing secrets.
Open module
VettiGuard user guideAPI request logs
Observability32 / 36

Webhook operations

What this is for

Manages signed event endpoints, delivery history, retries, replay, and dead-letter operations.

When to use it

Use it when your application must react to VettiGuard lifecycle events or when a delivery fails.

How to use it

  1. Create an HTTPS endpoint and select events.
  2. Store the signing secret securely.
  3. Verify signatures against the exact raw body.
  4. Send a test event.
  5. Investigate failed deliveries and replay only after the receiver is fixed.
Open module
VettiGuard user guideWebhook operations
Observability33 / 36

Monitoring and alerts

What this is for

Shows health, latency, queue, worker, webhook, and failure-rate signals with an operator alert lifecycle.

When to use it

Use it during incidents, after releases, or for regular service-health review.

How to use it

  1. Review current signals and trends.
  2. Open active alerts.
  3. Assign, acknowledge, and add investigation notes.
  4. Silence repeated notifications only for a bounded period.
  5. Resolve after the signal recovers and the cause is understood.
Open module
VettiGuard user guideMonitoring and alerts
Support34 / 36

Service status

What this is for

Shows VettiGuard public service availability, active incidents, maintenance windows, and recent operational history.

When to use it

Use it when an integration appears unavailable, when a maintenance notice is active, or when you want public incident updates by email.

How to use it

  1. Open the status page before raising a support inquiry.
  2. Review the overall status and affected components.
  3. Read the latest incident timeline or maintenance window.
  4. Subscribe with your email address and confirm the subscription.
  5. Use the personal link in the confirmation email to unsubscribe when required.
Open module
VettiGuard user guideService status
Account35 / 36

Account security

What this is for

Manages your own password, MFA, passkeys, trusted browsers, sessions, and account-recovery controls.

When to use it

Use it after first sign-in, when a device changes, or whenever you suspect account exposure.

How to use it

  1. Register at least one passkey when supported.
  2. Enable MFA and store recovery codes safely.
  3. Review active sessions and trusted browsers.
  4. Revoke anything you do not recognise.
  5. Change your password after suspected compromise.
Open module
VettiGuard user guideAccount security
Help36 / 36

Support and inquiries

What this is for

Use the inquiry channel when you need implementation guidance, account assistance, partnership information, or a security and privacy contact.

When to use it

Contact VettiGuard after checking the relevant module page and developer documentation, or immediately for a suspected security issue.

How to use it

  1. Open the public inquiry form.
  2. Choose the category that best matches your request.
  3. Include the affected module, reference ID, and safe diagnostic details.
  4. Do not include passwords, secret keys, response tokens, identity documents, or other sensitive evidence.
  5. Keep the inquiry reference shown after submission.
Open inquiry form
VettiGuard user guideSupport and inquiries

Use the arrow keys, page buttons, contents list, or swipe horizontally on a touch device.