Calisto Identity

Know who they are before they arrive.

A document scan, a face match and a liveness check, from a link the subject opens on any device. The result lands on the contact record every app already reads.

Billed per approved verification

Identity · Verifications
Status
Tier
StatusTierDocumentCountryAMLDate
ApprovedIdentity + CompliancePassportDominican RepublicClear8/7/2026
ApprovedIdentity CheckNational IDSpain8/7/2026
In ReviewIdentity + CompliancePassportNigeriaReview8/6/2026
ApprovedIdentity CheckDriving licenceUnited Kingdom8/6/2026
PendingIdentity CheckNational IDColombia8/6/2026
ApprovedIdentity + CompliancePassportGermanyClear8/5/2026
DeclinedIdentity CheckDriving licenceUnited States8/5/2026
ApprovedIdentity CheckResidence permitPortugal8/4/2026
ApprovedIdentity + CompliancePassportJapanClear8/4/2026
ExpiredIdentity CheckNational IDItaly8/4/2025
PendingIdentity + CompliancePassportBrazilPending8/3/2026
ApprovedIdentity CheckPassportCanada8/3/2026
The Dashboard

Verified, pending, declined, and the ones that need a human.

The verification operation at a glance, then the queue underneath it. AML hits are their own tile because they are their own decision.

Verified
1,284
Pending
37
Declined
52
AML Hits
4
Normal
At Risk
Critical
StatusTierDocumentCountryDate
ApprovedL2PassportDO8/5/2026
ApprovedL2National IDZA8/5/2026
PendingL1Driving LicenceES8/4/2026
ApprovedL1PassportKE8/4/2026
DeclinedL2National IDMA8/3/2026
ApprovedL2PassportFR8/3/2026
PendingL1Residence PermitDO8/2/2026
ApprovedL2PassportGB8/2/2026

Verify once. Every app knows.

A verification tool that stands on its own has to hand its answer to somebody. It verifies a person, keeps the result in its own database, and then the operator exports a file, wires an automation, or updates four systems by hand so the front desk, the door, the loyalty tier and the contract all know the same thing. Calisto Identity writes the result onto the contact record that reception, the door, the ticket desk, the help desk and the signature request already read. There is nothing to export, because there is nowhere to export it to.

The Trust Layer

0

verification tiers, identity and compliance

<0 min

end to end, in the browser

Zero

app installs for the person verifying

The Verification

ID scan, selfie, face match. Under two minutes.

The subject opens a link on whatever device is in their hand. No app install, no account to create. They photograph their document, take a selfie, and the match runs. What the operator gets back is this screen: the extracted document fields, the face match score, the liveness result, the screening outcome, the captured images held redacted, and the timeline of everything that happened. An approved verification is written onto the contact record every other app already reads.

Verification
Verified, ID + Compliance
Refresh
Decision
Tier
Identity + Compliance
Status
approved
Document
Passport
Country
PT
Liveness
passed
Face match
0.97
Verified
Mar 14, 09:41
Expires
Jun 12, 09:41
Source
link
AML Screening
Result
clear
Risk score
0.04
Match score
0.00
Captured documents
ID document
Redacted
Selfie
Redacted

Personal data is redacted. Reveal to view for compliance review, audited.

Event timeline
  1. created09:38:02
  2. approved09:41:06
  3. document_revealed11:20:31
The Level Is Derived, Never Stored

A contact badge level is computed from the latest approved verification that has not expired. An expiry passes and the level drops on its own. Nothing has to be swept, and no stale flag can outlive the check it came from.

Redacted Until Someone Reveals It

The document image, the selfie, the extracted name, the document number and the date of birth are hidden by default. Reveal shows them and writes an event, so the record of who looked sits in the same trail as the record of what was decided.

Four Signals, One Decision

The document is read and its fields extracted, the selfie is matched against the document photo with a score, liveness confirms a person rather than a photograph of one, and on the compliance tier the screening runs. The row carries all four.

Every Verification Names Its Origin

The row records which app asked for it. A check triggered from the reception board, from a shared link, from a document about to be signed or from a credential about to be issued stays distinguishable months later.

A Poll Sits Under The Webhook

The decision arrives by signature-verified webhook. When one does not arrive, the verification can be re-read from the provider and the same row updated, so a dropped delivery is a delay rather than a verification stuck at pending forever.

Expiry Is A Setting, Not A Constant

Thirty, sixty, ninety, a hundred and eighty or three hundred and sixty five days, or never. The operator chooses once in settings and every verification inherits it.

Two Tiers

Identity Check, or Identity plus Compliance.

Tier 1 is the document, the face match and the liveness result. Tier 2 is all of that plus screening against sanctions lists, politically exposed persons databases and adverse media, with a risk score and a match score written onto the same record. A front desk confirming that the guest is the guest needs Tier 1. An operator onboarding a counterparty with a compliance obligation needs Tier 2. The tier is set on the link, on the bulk run, or as the account default, and it can be changed for a single verification without changing anything else.

What runs
Tier 1Identity Check
Tier 2Identity + Compliance
Document scan and field extraction
Face match against the document photo
Liveness
Badge on the contact record
Event trail and audit record
Shareable self-serve link
Bulk verification
Sanctions screening
Politically exposed persons screening
Adverse media screening
Risk and match scores on the record
Case queue on a screening hit
Per verification, on the operator wallet. Pricing for both tiers is at the foot of this page.
The Tier Is Chosen Per Verification

Every link carries its tier. Every bulk run carries its tier. The account has a default, and any single verification can leave it. A lobby check and a compliance onboarding can run side by side in the same account on the same day.

Only An Approved Verification Bills

Setting up costs nothing. Creating a session costs nothing. A declined or expired session costs nothing. The metered event is an approval, deducted from the operator wallet at the moment the decision lands.

Both Tiers Produce The Same Record

The same badge on the same contact, the same audit trail, the same visibility in every sibling app. The compliance tier adds screening to the decision; it does not create a second kind of verification.

Compliance

Hand an auditor the screen you already work in.

Every event timestamped, every reviewer named, every case closed with a note. Nothing to assemble when somebody asks.

AML Screening

Sanctions, PEP and adverse media. One screening result.

A Tier 2 verification is screened against sanctions lists, politically exposed persons databases and adverse media sources. The outcome is clear, hit, or review, carried with a risk score and a match score on the verification itself. A hit or a score above the review threshold sends the verification to the case queue instead of approving it. Everything below the line approves, unless the operator has set the threshold to hold every compliance-tier result for a human.

AML Screening
Sanctions, PEP, and adverse-media screening results
184
Clear
3
Hits
7
Review
ResultRiskMatchDate
clear0.040.00Mar 14
review0.610.58Mar 14
clear0.090.00Mar 13
hit0.920.88Mar 13
clear0.020.00Mar 12
clear0.110.03Mar 12
Three Sources, One Result

Sanctions lists, politically exposed persons databases and adverse media are screened together and land as a single outcome on the verification: clear, hit, or review.

Two Numbers, Not A Verdict

A risk score and a match score sit beside the outcome. A near-miss on a common name and a genuine list match are different numbers, and the operator sees which one they are looking at.

The Thresholds Are Yours

One threshold sends a screening to review, another declines it. Both are set in settings, so an operator with a low tolerance and an operator with a high one run the same screening against different lines.

A Later Hit Does Not Rewrite History

When a name appears on a list after the fact, the screening result updates and the verification is flagged, but the decision that was already made keeps its own status and its own timestamp.

Screening Belongs To The Verification

The result is not a separate compliance record filed somewhere else. It is on the row, in the detail view, in the audit trail, and in the same list an operator filters by tier and status.

Tier 1 Says So Plainly

A Tier 1 verification opens the same detail screen and states that no screening ran, rather than showing an empty panel that could be read as a clear result.

Case Management

Every flagged verification gets a case. Every case gets a resolution.

A screening hit, a score above the review threshold, or an operator who has chosen to hold compliance-tier results puts the verification into the case queue instead of approving it. The case opens as the review control sitting on top of the full verification: the decision, the screening scores, the captured documents and the timeline. The reviewer clears and approves, keeps it in review, or declines, and the notes they write go onto the audit trail with their decision.

Case Management
Flagged verifications awaiting resolution
StatusAMLTierOpened
in_reviewhitIdentity + ComplianceMar 14
in_reviewreviewIdentity + ComplianceMar 14
in_reviewreviewIdentity + ComplianceMar 13
in_reviewhitIdentity + ComplianceMar 11
Review
Case opened Mar 14, 09:52
AMLhit
Risk0.92
Match0.88
Review notes (recorded on the audit trail)
Clear & approveKeep in reviewDecline
Below the review control
Decision grid, screening scores, captured documents, event timeline
A Case Is The Verification, Not A Copy Of It

Opening a case opens the review control on top of the whole verification detail: the decision grid, the screening scores, the captured documents and the event timeline. Nothing has to be looked up in a second place.

Three Outcomes, All Recorded

Clear and approve, keep in review, or decline. Whichever the reviewer chooses is written with their notes as an event on the trail, so the resolution and the reasoning stay attached to the record they belong to.

Nothing Resolves Itself

A flagged verification stays flagged until a person acts on it. There is no timer that approves by default and no rule that quietly clears a queue nobody looked at.

The Queue Is A Count On The Cockpit

Open cases show as an AML hits tile on the daily dashboard, in the error tone, so a queue that is growing is visible from the screen an operator already opens first.

Audit Trail

Every event. Every timestamp. Every reviewer.

A verification is created. A decision arrives. A screening returns a hit. A case is opened and resolved with notes. A redacted document is revealed. A verification reaches its expiry. Each of those is a row against the verification it belongs to, with a timestamp, and each row links back to the record. This is the trail an auditor reads, and it is the same one the operator reads, because there is only one.

Audit Trail
Every verification event, for compliance reporting
EventVerificationWhen
document_revealed8f3c…a410Mar 14, 11:20
reviewedd21b…77e9Mar 14, 10:38
aml_hitd21b…77e9Mar 14, 09:59
approved8f3c…a410Mar 14, 09:41
created8f3c…a410Mar 14, 09:38
declined5a90…21cdMar 13, 17:04
in_reviewb7e4…9931Mar 13, 15:22
expired10df…6c02Mar 12, 00:00
Nine Events, One Vocabulary

Created, pending, in review, approved, declined, expired, screening hit, reviewed, document revealed. Every row uses the same words the rest of the app uses, so the trail reads the same way the screens do.

A Row Is A Link

Every event points back at the verification it belongs to. Reading the trail and reading the record are one movement, not an export and a lookup.

Looking Is An Event

Revealing a redacted document writes a row. The audit trail therefore answers who saw the personal data, not only what the system decided about it.

The Reviewer Is Named

A resolved case records who resolved it, when, and what they wrote. The trail carries the human decision beside the automated ones.

Distribution

Send a link. The subject verifies themselves.

No app install. No Calisto account. A page that works on any device, in any browser, carrying your name and not ours.

The check is done and the record exists. What happens to it next is the part that matters.

One Contact. Every App.

Verified once. Recognised on every screen that shows them.

A verified identity here is not a row in a separate system waiting to be exported. It is a status on the contact record that reception, the door, the ticket desk, the help desk, the signature request, the payout and the schedule all already read. One person verifies once, and every screen that shows that person shows it.

One verificationapprovedwrites the status and the date onto the contact record
RegistryGate

Membership registration is held until the enrollee clears the required level.

BookingsGate

The reception board holds the check-in confirm behind the same gate.

TicketsGate

Attendee rows carry the checkmark, and an age-restricted door holds until it is met.

AccessGate

Issuing a keyless credential is held until the holder is verified.

DirectGate

A creator payout is held, and the public profile shows the checkmark.

DeskBadge

The customer context header shows the requester level and opens the panel in place.

InboxBadge

The contact sidebar shows the checkmark beside the name in the conversation.

LinkBadge

The contact card shows it before a reply is written.

SignBadge

The prepare panel shows a level for every signer bound to a contact.

WorkforceBadge

A staff lane on the schedule carries the level of the person working it.

One Write, Not Ten Integrations

An approved verification writes its status and its date onto the contact row. There is no export, no sync job and no webhook to build, because there is no second database to move it into.

The Badge Is Read, Never Stored

Each app asks for the level and gets it derived from the latest approved verification that has not expired. No app keeps its own copy, so no app can hold a level that is out of date.

A Gate Is A Wrapper, Not A Rebuild

Blocking a step on identity is one component around the step. Reception check-in, credential issuance, membership registration, a payout and a restricted door all use the same one, at whichever level that operator required.

Verification Happens Where You Are

When a contact is not verified yet, the capture flow opens inside the app that asked. Nobody is sent to a different product to come back afterwards, and nothing is read only in the app that did not write it.

Two Sightings, One Person

The alias index maps an email, a phone number, a chat handle or a messaging address to a single canonical contact per account. The same address seen in a different app resolves to the same person rather than creating a second one.

Provenance On Every Link

Each alias carries a confidence score, who or what linked it, and which app it came from. A provisional match and an exact one are distinguishable, which is what makes a merge reviewable instead of permanent.

Connections

A verification is worth what the rest of the system does with it.

Identity
The Contact
Gated Steps
The Checkmark
Scope And Brand
The Cockpit
Metered Usage

The Contact

Identity → the contact record

An approved verification writes its status and its date onto the contact row itself, and the badge every app renders is derived from the latest approved verification that has not expired. Nothing is copied, so nothing can go stale.

Gated Steps

Identity → Registry · Bookings · Tickets · Access · Direct

Membership registration, reception check-in, an age-restricted door, credential issuance and a creator payout are each one component wrapped around the step, holding it until the contact meets the level that operator required.

The Checkmark

Identity → Desk · Inbox · Link · Sign · Workforce

The same inline badge renders beside a contact name in a ticket, a conversation, a contact card, a signature request and a staff lane, and clicking it opens the detail in place rather than sending anybody to another product.

Scope And Brand

Identity → Purview

The active business unit decides which verifications are visible, and the business name and brand the subject sees on the capture screen are the shared configuration, edited from inside Identity without leaving it.

The Cockpit

Identity → Today

Verified, pending and screening hits arrive as tiles on the daily dashboard, with the hits tile in the error tone, so a review queue that is filling up is visible from the first screen of the day.

Metered Usage

Identity → the operator wallet

Only an approved verification bills, captured at the moment the decision lands, in the currency the account operates in. An account whose currency cannot be resolved is not charged in a guessed one.

Companion apps

Where Identity touches everything else.

8 of these 12 connections are in your plan today. The rest stay visible so you know the instrument is there before you need it.

Registry
Calisto CoreIn your plan
Registry

Registering a new member runs inside the verification gate, so the membership record cannot be created until the enrollee has cleared the level the operator required.

Bookings
Calisto CoreIn your plan
Bookings

The reception board wraps the check-in confirm in the verification gate, resolving the guest through the contact the reservation already carries.

Tickets
Calisto CoreIn your plan
Tickets

The attendee list carries a verification column resolved in one batched read per page, and an age-restricted event holds the door until the holder meets the required level.

Inbox
Calisto InteractIn your plan
Inbox

The contact sidebar renders the checkmark beside the name and opens the verification panel in place, without leaving the conversation.

Link
Calisto InteractIn your plan
Link

The contact card carries the same checkmark, so the person on the other end of a message is identified before a reply is written.

Workforce
Calisto CoreIn your plan
Workforce

A staff lane on the schedule carries the verification level of the person working it, resolved through their contact record.

Today
Calisto OpsIn your plan
Today

Three tiles roll into the cockpit from Identity itself: verified, pending, and AML hits waiting on a reviewer.

Purview
Calisto CoreIn your plan
Purview

The active business unit scopes which verifications are visible, and the business name and brand on the capture screen are edited from inside Identity settings.

Desk
Calisto OpsNot in this plan
Desk

The customer context header carries the requester verification level, and clicking it opens the panel where an agent can trigger a fresh verification from the ticket.

Access
Calisto OpsNot in this plan
Access

Issuing a credential runs inside the verification gate, so a keyless pass is never handed to an unverified holder.

Sign
Calisto CommerceNot in this plan
Sign

The prepare panel resolves a verification level for every signer bound to a contact, so the sender can see who is identified before the document goes out.

Direct
Calisto CreateNot in this plan
Direct

A creator payout runs inside the verification gate, and the public creator profile renders the checkmark at full size.

Pricing

No setup cost. Pay when you start using.

ID verification for hospitality and regulated venues.

Calisto Identity

KYC identity verification.

€1per Level 1 check
Level 2 check
€2.50/check
Spec Sheet

Everything included in Calisto Identity.

Verification
  • Two tiers: identity check, and identity plus compliance
  • Document scan with field extraction: type, country, number, expiry, name, date of birth
  • Selfie captured and matched against the document photo, with a score on the record
  • Liveness result on the record
  • Captured images stored on the verification and rendered redacted by default
  • Reveal for compliance review, which writes its own audit event
  • Five statuses: pending, approved, declined, in review, expired
  • Expiry configurable per account, from thirty days to never
  • Required document type configurable: any, passport, national ID, or driving licence
  • Age threshold setting for age-gated flows
  • Every verification records the app that triggered it
Compliance
  • Sanctions, politically exposed persons and adverse media screening on the compliance tier
  • Three outcomes: clear, hit, review
  • Risk score and match score written onto the verification
  • Review threshold and decline threshold set per account
  • Screening dashboard with clear, hit and review totals
  • Case queue for every flagged verification
  • Case detail is the review control on top of the full verification record
  • Three resolutions: clear and approve, keep in review, decline
  • Reviewer, timestamp and notes recorded on resolution
  • Tier one states plainly that no screening ran, rather than showing an empty result
Audit Trail
  • Every lifecycle event as a timestamped row against its verification
  • Created, pending, in review, approved, declined and expired
  • Screening hit recorded as its own event without overwriting an existing decision
  • Case resolution recorded as a review event
  • Document reveal recorded as an event, so access to personal data is on the trail
  • Every row links back to the verification it belongs to
  • Registered in the manager area of the menu
Distribution
  • Shareable verification links with a label and a tier
  • Public capture page rendered outside the authenticated shell, with no account for the subject
  • Name and email bound to a real contact before capture starts
  • Document and selfie captured in the browser
  • Use count per link
  • Revoke a link without touching the verifications it produced
  • Logo and custom message on the capture screen, set in settings
  • Business name and brand edited from inside Identity through the shared configuration block
  • Bulk verification from a pasted list of contacts at a chosen tier
  • Verification triggered in place from any app that renders a contact
Where You Work
  • Dashboard with verified, pending, declined and screening hit totals, plus recent activity
  • Verifications list filtered by status and by tier
  • Verification detail with the decision grid, screening, captured documents and timeline
  • Screening list with risk and match scores
  • Case queue and case detail
  • Audit trail
  • Verification links with a creation dialog
  • Bulk verify
  • Reports with pass rate, total checks, tier split and a per-country table
  • Settings across verification, screening, cost reporting, notifications and branding
Everywhere Else
  • Inline checkmark rendered beside a contact name in any app
  • Expandable panel that opens in place, never a redirect to another product
  • Capture flow that opens inside whichever app asked for it
  • Gate that holds a transactional step until a required level is met
  • Level derived on read from the latest approved, unexpired verification
  • Status and date written onto the contact record itself
  • List reads batched per page, never one lookup per row
  • Alias index resolving an email, phone, chat handle or messaging address to one canonical contact
  • Confidence score and provenance on every alias link
Billing And Reporting
  • Metered per approved verification against the operator wallet
  • Setup, session creation, declined and expired verifications are not charged
  • Charge captured at the moment the decision lands
  • Currency derived from the account operating currency and never guessed
  • An unresolved currency skips the charge rather than billing in a defaulted one
  • Insufficient funds is non fatal and collected on the next top up
  • Usage summary by period, split by tier
  • Your own list price and currency for the estimated cost figure on reports, or blank to hide it
  • Notification webhook on completion and on a screening hit
Connected to Calisto Pro
  • Registry (membership registration held behind the gate)
  • Bookings (reception check-in held behind the gate)
  • Tickets (attendee checkmarks, and an age-restricted door)
  • Access (credential issuance held behind the gate)
  • Desk (requester level in the customer context header)
  • Inbox (the checkmark in the contact sidebar)
  • Link (the checkmark on the contact card)
  • Sign (a level for every signer bound to a contact)
  • Direct (payout gate and the public creator profile checkmark)
  • Workforce (the level of the person working a schedule lane)
  • Today (verified, pending and screening hit tiles on the cockpit)
  • Purview (business unit scope, and the brand on the capture screen)
Honest answers

Questions about Calisto Identity

A link they open on any device: a document scan, a face match and a liveness check. No app to install, which matters when the subject is a guest arriving tomorrow rather than an employee.

On the contact record every app already reads, as a verification level. That is why a booking, a rental or a door can gate on it without integrating with anything.

Yes. Gated steps are chosen per flow, so a low-value booking passes straight through and a high-value rental or a first key collection requires the check.

As you. Scope and brand are configurable, so the subject sees your business rather than a vendor they have never heard of.

Metered usage: you pay for checks performed. The pricing section on this page reads the live catalogue and is the authority.

The verification result stays on the contact and the underlying document handling follows the retention you configure. Verification outcomes export with the contact record.