Skip to content

How to add device intelligence with Myaza Trust

Device Intelligence adds context from the device and network used during capture. Configure the findings your team cares about and use them with other evidence rather than treating every shared device as fraud.

Charles Archibong

, Co-founder

· 4 min read

Myaza Trust editorial illustration: Recognise the risk in a device.

Key takeaways

  • The same workflow is used by the deployed capture journey.
  • Unsupported signals remain unavailable rather than false.
  • A configured Review finding reaches human review.
  • Your backend applies the final action to the correct account.

Device Intelligence adds context from the device and network used during capture. Configure the findings your team cares about and use them with other evidence rather than treating every shared device as fraud.

Before you begin

  • A verification workflow with Device Intelligence configured

  • Supported capture signals and app registration where app integrity is required

Use a team member with permission for this control. Check the organisation and environment before changing a setting. Review the current price before a paid check or ongoing enrolment. Screenshots show an example workspace or the public integration reference; they do not show a real customer or a completed paid check.

Set up and use the capability

Step 1: Open the verification workflow

Choose the correct organisation and Sandbox. Open Configuration → Workflows and select the workflow your customers use. Device Intelligence is under After Capture. Check that it is enabled, then select it. Capture signals vary by SDK, operating system and permissions; a workflow setting cannot manufacture a signal the client does not collect.

Step 2: Individual verification workflow editor and its workflow ID

Dashboard example: Open the verification workflow

Step 2: Review country restrictions

Open Countries. The Restrict sessions by country switch controls the IP-based geofence. Leave it off if your policy accepts customers travelling abroad. If you enable it, choose the allowed countries deliberately and test the blocked journey. IP country is network evidence; it is not proof of nationality or precise physical location.

Dashboard example: Review country restrictions

Dashboard example: Review country restrictions

Step 3: Decide what each finding does

Open Rules. Review the supported device and IP findings and choose Approve, Review or Decline in line with your policy. Review can require a matching enabled decision rule. Check your decision graph’s order and preserve unrelated rules. A recovered device, VPN or shared phone can have a legitimate explanation, so route the evidence rather than making an unsupported identity claim.

Integration reference: Capture add-ons

Integration reference: Capture add-ons

Step 4: Register mobile apps where needed

For app-integrity evidence, register your application under Settings → Mobile apps and follow the relevant native SDK setup. App Attest and Play Integrity depend on platform configuration; a toggle in the workflow is not sufficient. Match the registered app to the environment and identifiers your build actually uses. For browser capture, use the supported browser evidence instead of promising native app-integrity signals.

Integration reference: React Native SDK

Integration reference: React Native SDK

Step 5: Save and publish the workflow

Wait for Saved in the editor. Select Publish, or Publish changes for an existing workflow. In the publication review, check the target environment, workflow ID, price and readiness warnings. Resolve blocking issues, then confirm Publish version. A saved draft is not the version customers use. New sessions use the new published snapshot; sessions already created retain their original version.

Step 8: Publication review showing the target environment, workflow ID and confirmation button

Dashboard example: Save and publish the workflow

Step 6: Connect the published workflow to your app

Copy the workflow ID. Give that ID to your supported Web, React Native or Flutter SDK, with a publishable key from the same organisation and environment and a stable customer reference. Alternatively, create a customer-bound hosted session on your backend with POST /api/kyc/sessions, using a secret key. Return the session URL only to the intended customer. A camera preview does not run a verification or prove your backend handles the result.

Integration reference: Request

Integration reference: Request

Step 7: Read the final outcome on your backend

After capture, store the verification ID against your own customer reference. Follow status updates or retrieve current status. Read status for the outcome and checkStatus, reason and reasonCode for the explanation. When a workflow has decision rules, a checks-completed event can arrive before the final workflow decision. Keep processing and human-review results pending; do not approve an account merely because the customer finished the camera screens.

Integration reference: Status and checkStatus

Integration reference: Status and checkStatus

Get more from the capability

  • Use stable device references in subsequent activity assessments so your app can build useful device history.

  • Combine device evidence with a subject-bound face check when a new device requires extra assurance.

  • Test the finding and its resulting decision separately. A signal being recorded does not itself restrict an account in your app.

Test before relying on it

Run the supported Sandbox or simulator scenarios for this product. Where a tool is Production only, check access and scope first, then use only a permitted, deliberately reviewed Production test. A documentation screenshot or a successful page load is not an end-to-end integration test.

  • The same workflow is used by the deployed capture journey.

  • Unsupported signals remain unavailable rather than false.

  • A configured Review finding reaches human review.

  • Your backend applies the final action to the correct account.

Troubleshooting

App integrity is absent

Check the mobile app registration, platform setup and SDK support for that build.

Review does not happen

Check enabled decisioning, the relevant rule and rule order.

A legitimate customer is blocked on a VPN

Review the policy choice and evidence. Do not assume an IP finding proves fraud.

Open the setup and integration references

Open Workflows

Read the integration reference

Back to Solutions. Choose the capability you want to activate, then follow its own guide.

Sources

Charles Archibong

About the author

Charles Archibong

Co-founder

Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.

  • Myaza Trust editorial illustration: Know the company. Check who controls it.

    Identity Verification

    How to verify a business with Myaza Trust

    Verify a business against a supported registry and choose the additional evidence your onboarding policy needs. Company existence and authority to represent it are different questions.

Build your product.We'll handle the rest.

Identity and compliance, end to end, built to global standards, priced for founders.