11Industries · Gig economy

Same-day onboarding, a live face at every shift

Workers join fast, switch between apps, and often arrive through partner fleets or agencies. SenseCrypt enrolls each one from the photo you already verified, and your platform can ask for their live face whenever a shift starts.

01The ceremony

From sign-up to shift start

  1. Identity check you already ran

    The verified photo becomes the enrollment

  2. Same-day activation

    Activate once on their own phone; no password ever exists

  3. Live face at shift start

    Your platform asks; only the enrolled worker can approve

  4. Named session + audit event

    Revoke when the worker or the partner leaves

02The outcomes

What platforms run on: SenseCrypt

For your workforce

Onboard the same day

The photo from your identity check becomes the enrollment, so a newly approved worker can sign in the same day, with no password to set.

A live face when the shift starts

Your platform can ask for the live face again at shift start or before a high-value job, and only the enrolled worker can approve it.

Their phone is the credential

Workers approve in the authenticator app on the phone they already carry. There is no password to share and no code to pass along.

Offboarding in one step

When a worker leaves, deactivate them once, through SCIM or the console, and their SenseCrypt sign-in stops working for every connected app.

For partners & B2B

Fleets and agencies, isolated per partner

Each fleet operator or staffing agency gets a tenant of its own: their own users, their own branding, and an audit trail per partner.

Delegated admin for partners

Partner managers run their own workers inside roles you define. Central policy, local speed.

03The failure modes

What gets in the way today

The account holder isn't always the worker

Accounts get lent, rented, or sold, and the person doing the job may not be the person who passed the checks.

Waiting costs shifts

Every day an approved worker waits for credentials is a shift the platform doesn't fill.

A saved password signs in anyone

A password saved on a shared phone signs in whoever picks it up next.

Partners you don't manage

Fleet operators and agencies bring their own workers, and their access outlives the relationship when nobody owns switching it off.

Checks that happen once

Identity checks run at sign-up; after that, nothing confirms the same person is still behind the account.

Disputes need a name

When a complaint lands, a shared login can't tell support which person actually did the job.

04The compliance map

What the regulator sees

Every worker and partner runs on the same rails, with no passwords to leak and no face image or template to defend, only sealed, unlinkable tokens that even we cannot reverse into a face and that hold no PII.

NIST SP 800-207 — Zero Trust Architecture

Every shift can start with a fresh verification of the named worker, and access is granted per session with the least privilege the job needs. That maps to the per-session access and least-privilege tenets of Zero Trust Architecture.

Read the source

GDPR — data minimisation (Art. 5(1)(c))

Workers verify without any stored face image or template, so the only thing held is a sealed, unlinkable token that even we cannot reverse into a face and that holds no PII, even for a workforce spread across partners and borders. That supports GDPR's data-minimization principle.

Read the source

Face matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)

GDPR PDPA CCPA
Built from the same three solutions: Customer identity Workforce SSO B2B SaaS

Onboard today, verify every shift

Start with one city or one partner fleet, then widen it.