figma guide
Designing breach settlement claimant identity re-verification and step-up UI in Figma: IDV-* challenges, ACT-* requests, and portal lock states
Design breach settlement claimant identity re-verification UI in Figma with IDV-* step-up challenges, ACT-* document requests, portal lock states, and fraud-safe messaging.
- Published
- Updated
- Aug 30, 2026
- Read time
- 7 min
- Level
- Intermediate
Quick answer
Identity re-verification UI lets settlement programs prove claimants are who they say they are before releasing high-risk PAY- or clearing FRD- holds—without turning the portal into a permanent lockout.** Design IDV- verification sessions* triggered by risk signals, ACT- action requests* for specific documents, and graded portal lock states (read-only vs full block) with email OTP and government ID upload paths. Claimants see “verify your identity” not “fraud investigation”; admins see IDV-* scores, document review queues, and CLM-* match results. Connect to fraud detection, eligibility portal, document upload, payment disbursement, and session re-auth. Start from the Figma guides hub and pair with forms, file upload, and Dev Mode handoff.
Who this is for
- Product designers building step-up flows when settlement integrity requires stronger proof than initial claim filing.
- Identity and fraud teams configuring when IDV-* triggers fire relative to DUP-* matches and PAY-* thresholds.
- Claims administrators who need counsel-approved verification steps that survive audit and avoid discriminatory friction.
When step-up identity verification triggers
IdvTrigger — Why IDV-* fires (configurable rules)
├── Automatic triggers:
│ ├── [FRD-* hold](/designing-breach-settlement-duplicate-claim-detection-and-fraud-prevention-ui-in-figma/) cleared pending ID proof
│ ├── PAY-* amount above threshold · First-time bank change
│ ├── [Amendment](/designing-breach-settlement-claim-amendment-and-correction-ui-in-figma/) changing legal name or SSN
│ ├── [Deceased/heir](/designing-breach-settlement-deceased-claimant-and-heir-designation-ui-in-figma/) or [minor/guardian](/designing-breach-settlement-minor-claimant-and-guardian-designation-ui-in-figma/) path
│ ├── [Foreign claimant](/designing-breach-settlement-foreign-claimant-and-international-payment-ui-in-figma/) without prior W-8 match
│ ├── Device/IP anomaly vs [eligibility verification](/designing-breach-victim-eligibility-verification-portal-ui-in-figma/) session
│ └── [Returned payment](/designing-breach-settlement-returned-payment-and-reissue-ui-in-figma/) + payee change
├── Manual triggers:
│ ├── Investigator ACT-* from console
│ ├── [Call center](/designing-breach-call-center-and-agent-script-ui-in-figma/) escalation
│ └── Counsel-ordered verification campaign
└── Outcomes:
├── pass → Release locks · Resume PAY-* / FRD-* clear
├── fail → Deny or escalate · No raw vendor error to claimant
└── expire → Reminder series · Portal soft lock
| Risk tier | Typical IDV-* method | Portal lock level |
|---|---|---|
| Low | Email OTP reconfirm | None · banner only |
| Medium | SMS OTP + security questions | Soft lock: view status, no edits |
| High | Government ID + selfie liveness | Hard lock until IDV-* pass |
| Critical | In-person or notary (out of band) | Full block + mailed instructions |
Verdict: Match verification strength to risk—do not require passport upload for every $25 check reissue.
IDV-* session structure and vendor handoff
IdvSession — IDV-992-0312 · CLM-992-44102 · Method: id_doc_selfie · Status: pending_review
├── Session fields:
│ ├── idv_id (IDV-*) · clm_id · trigger_reason_enum
│ ├── method_enum (otp_email · otp_sms · id_doc · id_doc_selfie · knowledge_based)
│ ├── vendor_ref (external—internal admin only)
│ ├── started_at · expires_at · attempt_count
│ └── result: pending · pass · fail · expired · manual_review
├── Claimant steps (id_doc_selfie example):
│ ├── 1. Consent + [privacy notice](/designing-privacy-notice-version-management-and-policy-changelog-ui-in-figma/) link
│ ├── 2. Select ID type (license · passport · state ID)
│ ├── 3. [Upload](/designing-file-upload-and-drag-drop-ui-in-figma/) front/back · Camera capture mobile
│ ├── 4. Selfie liveness (vendor widget—frame in Figma)
│ ├── 5. Processing spinner · "Usually 2–5 minutes"
│ └── 6. Pass/fail/pending_review screen
├── Admin review queue (manual_review):
│ ├── Side-by-side: ID image · CLM-* filed identity · [eligibility row](/designing-breach-victim-eligibility-verification-portal-ui-in-figma/)
│ ├── Approve · Reject · Request clearer photo (new ACT-*)
│ └── AUD-* on every decision
└── Fail handling:
├── Claimant: "We couldn't verify—try again or contact support"
├── Max 3 attempts · then phone/call center path
└── No display of "facial match 12%" scores
Embed vendor iframe boundaries in Figma with loading, error, and timeout variants—identity vendors fail often on mobile Safari.
ACT-* action requests and portal lock states
ActionRequest — ACT-992-0440 · CLM-992-44102 · Type: upload_government_id
├── ACT-* types:
│ ├── upload_government_id · upload_proof_of_address
│ ├── confirm_bank_ownership · confirm_mailing_address
│ ├── complete_idv_session (links IDV-*)
│ ├── sign_affidavit (e-sign or upload)
│ └── schedule_phone_verification
├── Portal lock matrix:
│ ├── none — Full portal access
│ ├── soft — View [status](/designing-breach-settlement-claim-status-portal-and-claimant-dashboard-ui-in-figma/) · Complete ACT-* only · No amendments
│ ├── payment — Block PAY-* / REI-* until ACT-* cleared
│ └── full — Login shows ACT-* checklist only (rare · counsel approval)
├── Claimant checklist UI:
│ ├── Required ACT-* items with due dates
│ ├── Completed items with timestamp
│ ├── "What happens next" after each upload
│ └── Support phone · Business hours · ADA contact
└── Integration:
├── ACT-* blocks [payment disbursement](/designing-breach-settlement-payment-disbursement-and-payout-tracking-ui-in-figma/)
├── Cleared ACT-* may auto-clear FRD-* (configurable)
└── [Document management](/designing-breach-settlement-claim-document-upload-and-evidence-management-ui-in-figma/) stores DOC-* refs
Use badges for ACT-* status: Required · In review · Complete · Overdue.
Claimant-safe copy vs admin detail
CopyLayers — Same event, two audiences
├── Claimant portal:
│ ├── "Verify your identity to continue"
│ ├── "Upload a photo of your driver's license"
│ ├── "We're reviewing your documents—check back in 1–2 days"
│ └── Forbidden: FRD-* · DUP-* · fraud score · other CLM-* data
├── Email/SMS:
│ ├── Signed link to IDV-* or ACT-* · Expires 72h
│ ├── Plain language · No attachment of PII
│ └── Unsubscribe only for marketing—not legal notices
├── Admin / investigator:
│ ├── Full IDV-* vendor payload · Match scores (internal)
│ ├── Link to [fraud case](/designing-breach-settlement-duplicate-claim-detection-and-fraud-prevention-ui-in-figma/) if applicable
│ └── ACT-* assignment and SLA timers
└── Call center:
├── Script: verify last4 SSN · DOB · mailing zip
└── Cannot bypass IDV-* for PAY-* release without supervisor
Prototype component variants: audience=claimant vs audience=admin on shared ACT-* cards.
Comparison: IDV UI vs adjacent settlement surfaces
| Surface | Focus | This UI adds |
|---|---|---|
| Eligibility portal | Class membership | Stronger identity proof post-file |
| Fraud detection | DUP-* / FRD-* | Claimant path to clear holds |
| Document upload | Evidence storage | ID-specific ACT-* types |
| Email OTP | Account verify | Step-up inside claim journey |
| Session re-auth | Security timeout | Risk-based not just time-based |
Handoff checklist (Dev Mode)
- IdvSession — idv_id (IDV-*), clm_id, method_enum, trigger_reason_enum, status_enum, attempt_count, expires_at, vendor_ref (admin only).
- ActionRequest — act_id (ACT-*), clm_id, act_type_enum, due_at, status_enum, linked_idv_id, doc_refs[].
- PortalLockState — clm_id, lock_level_enum, blocked_actions[], allowed_actions[].
- IdvWizard — step_index, id_type_enum, capture_mode (upload | camera), vendor_widget_bounds.
- ActChecklist — act_items[] with status badges, overdue_flag, support_cta.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Full portal lock with no checklist | Claimant panic · support spike | Soft lock + visible ACT-* list |
| Show vendor “fraud score” to claimants | Harm · legal exposure | Generic retry copy |
| IDV-* required for all claimants | Abandonment · equity issues | Risk-tier triggers only |
| No mobile camera capture path | 70%+ mobile traffic fails | Native camera component |
| ACT-* without due date | Indefinite PAY-* block | Show deadline + reminders |
| Store ID images in claimant-visible gallery | PII overshare | Admin-only DOC-* classification |
| Skip consent before biometric | BIPA/GDPR issues | Consent step with policy link |
| Allow IDV bypass via call center | Fraud hole | Supervisor audit on exceptions |
| Same ACT-* UI as DSAR upload | Wrong retention rules | Settlement-specific DOC-* tags |
| No AUD-* on manual IDV approve | Court challenge | Log reviewer + timestamp |
Recommended workflow
- Define trigger matrix with fraud, disbursement, and counsel (amount thresholds, FRD-* paths).
- Design IDV- wizard* with vendor placeholder frames and all result states.
- Map portal lock levels to ACT-* combinations—prototype soft vs hard lock.
- Build admin manual review queue linked to document viewer.
- Write claimant-safe copy pack for pass, fail, pending, and overdue ACT-*.
- Connect cleared IDV- to PAY- release** and audit log entries.
FAQ
Claimant fails IDV-* three times?
Phone verification ACT- or call center appointment* · Do not auto-deny without human review on high-value claims.
Biometric consent for selfie liveness?
Yes where required · Separate consent checkbox · Link to retention policy · No optional skip if method requires selfie.
Guardian verifying for minor claimant?
IDV- on guardian identity* · Minor SSN from claim file · Guardian relationship affidavit ACT-*.
IDV-* during active dispute?
Verification independent of dispute merits · Can require IDV-* before accepting dispute filing or evidence.
Vendor outage during IDV-*?
Graceful degradation message · Extend IDV-* expiry · Queue manual review if urgent PAY-* · Status on trust/status page if widespread.
Next steps
- Design breach settlement duplicate claim detection and fraud prevention UI in Figma — FRD-* triggers for IDV-*
- Design breach victim eligibility verification portal UI in Figma — Upstream identity baseline
- Design breach settlement claim document upload and evidence management UI in Figma — DOC-* for ACT-* items
- Design email verification and OTP UI in Figma — Low-tier step-up
- Design audit log and security activity UI in Figma — IDV-* decision trail
§ Keep reading