Customer identity verification begins with a product question: what does your business need to know before someone can use a feature? A membership service may want access through an established account. A contract process may need a verified legal name. Those requirements lead to different onboarding designs.
This guide focuses on the first model: serving people through their underlying verified Gammal Tech accounts. It explains where document collection belongs, what your website can rely on, and how to turn a completed sign-in into a useful customer experience.
Define what your business needs to verify
Write down the decision your website must make before choosing an identity service. Be specific enough that your team can tell whether the available result answers the question.
- Account access: can this visitor authenticate to an accepted account and use project data your application previously stored?
- Identity evidence: does the business need a verified legal name, an identity attribute, or a document-verification report?
- Product eligibility: has this account purchased a plan, received an invitation, or met a separate requirement?
Gammal Tech’s hosted account flow addresses authentication. It does not disclose the underlying identity attributes or documents to your website. Product eligibility remains a separate business decision. Our digital identity verification explainer describes the difference between proofing an identity and authenticating an account.
How the verified-account model works
Gammal Tech requires national-ID verification when creating an account and applies a one-account-per-person rule. A real, verified person is behind the account, while Gammal Tech keeps the underlying identity records private from participating websites. The website uses the account sign-in service instead of creating its own identity-document collection process.
After the customer signs in, the website can check the session and use the supported account features. That session check confirms account access. It does not provide the customer’s verified name, an identity-document copy, a screening decision, or evidence that identity proofing has just been performed again.
This makes the model useful when the service needs account continuity without receiving an identity file. If your business must inspect specific identity evidence, compare that requirement with the separate service models in our identity proofing services guide.
Design the first visit and the returning visit separately
Existing Gammal Tech account holders and people creating their first account have different starting points. Explain the next step clearly for each group rather than assuming everyone arrives ready to sign in.
| Customer’s situation | What your website should explain |
|---|---|
| Already has a Gammal Tech account | Use the existing account in the official hosted sign-in flow, then continue with this website’s service. |
| Needs a first Gammal Tech account | Start at the official registration page and follow the current account requirements before returning to the service. |
| Has signed in successfully | Complete only the product choices or additional information needed for the task, such as selecting a workspace or choosing a display name. |
| Needs access to a paid or restricted feature | Explain the separate purchase, invitation, or approval requirement for that feature. |
Link new customers to Gammal Tech registration. Before advertising an onboarding deadline, confirm the current requirements for the customers you intend to serve. Keep account registration, account readiness, and completion of your own onboarding as separate milestones.
Account reuse still involves sign-in on participating websites. It does not automatically transfer another service’s membership or subscription. The guide to one account across multiple websites covers that wider account journey.
Keep the identity file separate from product information
Give each piece of application data an explicit purpose. Signing in does not give a developer access to Gammal Tech’s identity records. Your application cannot request the user’s email, phone number, national ID, legal name, or other underlying identity information through the API or SDK.
| Information | What the participating website receives |
|---|---|
| Account authentication | A session token and the ability to verify that the session is valid. |
| Underlying identity and contact details | Account email, phone number, legal name, national ID, and other identity information cannot be requested through the API or SDK. |
| Saved product information | The website can store supported per-user data it already knows, such as preferences or progress. It can retrieve only data its application previously stored, not additional information from Gammal Tech’s identity records. |
| Information requested by the website | Any display name, delivery address, or support message the website separately collects is its own collection decision. |
A customer-chosen display name is not a verified legal name. Similarly, a preference saved in the account does not prove age, professional qualifications, or entitlement to a paid feature. Keep those meanings clear in labels and business rules.
Keeping identity documents outside your systems reduces the copies you handle. It does not remove responsibilities for your own website or vendors. The FTC’s service-provider security guidance recommends assessing providers, setting written security expectations, and checking that those expectations are met.
Apply the model to a real customer task
A learning workspace
A learner signs in and resumes progress the learning website previously stored. The website can offer continuity through the account without asking the learner to upload an identity document to the learning platform. If the business later issues a certificate that must show a verified legal name, that introduces an additional requirement that login alone does not supply.
A paid member community
The community accepts Gammal Tech accounts, while its own membership process determines access to paid discussions. Account authentication and membership are separate checks. Moderation, community rules, and decisions about member conduct also remain part of operating the community.
A customer planning tool
A customer signs in, selects a project, and saves planning preferences. On the next visit, the website retrieves the preferences it previously stored. The product can make those task-specific choices the center of onboarding without requesting identity information from Gammal Tech.
These examples are product designs, not additional built-in services. Choose the flow around the information the task actually needs.
Prepare your onboarding before launch
- Name the account option clearly. Explain that customers will use Gammal Tech for account access, and make the next product step visible.
- Confirm the first-time journey. Review current enrollment requirements and timing for your intended audience. Do not promise immediate access before that review.
- Keep document handling in the official account flow. Avoid adding an identity-document upload form or asking support staff to collect identity scans for this integration.
- Define the information your own service needs. Record why each additional field is necessary and how it will be used.
- Decide access rules separately. Purchases, invitations, and administrative privileges need their own authoritative decisions.
- Test completion and interruption. Review existing-account sign-in, new-account instructions, a cancelled sign-in, and the customer’s return to the intended task.
For the website setup itself, use the guide to adding user login. For the business case and measurement plan, read reusable account benefits. Those guides cover integration and account convenience; the decision here is whether authentication through a verified account meets your service’s actual requirements.
Common questions
Does my website need to collect the customer’s ID documents?
Your website does not need to collect identity documents for Gammal Tech’s hosted account flow. The underlying account identity is handled by Gammal Tech. Any separate requirement your business has to obtain identity evidence must be evaluated on its own.
What does my website receive after the customer signs in?
It receives a session token and can use the documented session checks and account features. The API and SDK do not disclose the underlying account email, phone number, identity documents, or verified legal name. Saved-data retrieval returns only information the application previously stored; it cannot fill missing fields from Gammal Tech’s identity records.
Does a valid session mean a new identity check was completed?
No. A valid session confirms authentication to the account. It is not a fresh document-verification result, a background check, or evidence of a particular regulatory screening.
Can I promise instant onboarding to someone without an account?
Account creation and readiness are separate from signing in with an existing account. Confirm the current registration requirements and timing for your audience before making an onboarding promise.
References and further reading
- Gammal Tech integration reference — Session behavior, supported application storage, and the information boundary for participating websites.
- FTC: service-provider security — Guidance on evaluating, contracting with, and monitoring service providers.
- Digital identity verification explained — How identity proofing, account authentication, and product permissions answer different questions.