> ## Documentation Index
> Fetch the complete documentation index at: https://nuggets.life/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Know Your Employee (KYE)

Verify the person behind every remote developer login.

Nuggets KYE verifies employees and contractors at onboarding, binds their identity to your organisation, and gates access to code, cloud, SaaS, and internal systems on proof of the verified person. A credential alone is not enough.

Remote hiring fraud is now a security problem, not an HR problem.

In April 2026, the U.S. Department of Justice announced sentencings in a North Korean remote IT worker scheme involving stolen identities of at least 80 people, jobs at more than 100 U.S. companies, and over \$5 million in illicit revenue for the DPRK.

Fake candidates, substitute workers, shared credentials, laptop farms, remote desktop access, and AI-assisted identity fraud are putting unverified people inside corporate systems.

Background checks tell you who passed once. Nuggets KYE proves who is acting now.

## **The problem**

The person who passed onboarding may not be the person accessing your systems.

Most hiring checks happen once. A candidate verifies documents, passes interviews, receives credentials, and gets access. After that, the organisation usually trusts the credential.

That trust model is breaking. Documents can be fabricated. Video interviews can be coached or handed off. Passwords, passkeys, YubiKeys, and company laptops can be shared. Remote desktops can hide where the work is actually happening.

The vulnerability is structural. Traditional employment verification was built to check documents at a point in time. It was never built to bind identity to an ongoing working relationship, or to the person logging into your code, cloud, and SaaS tools every morning.

## **What KYE Does**

Nuggets KYE binds the verified individual at onboarding to the person accessing your systems. Credential handoff, substitute workers, and delegated access become materially harder to execute.

**Verified onboarding** 

Identity proofing at the point of hire. NFC e-Passport chip verification against government-issued cryptographic certificates, biometric and liveness checks, eligibility and risk signals.

The result is a reusable, holder-bound credential, not another document on file.

**Continuous identity binding** 

The verified identity is holder-bound to the individual using biometrics, liveness, and cryptographic proof, not just to a device, session, password, passkey, or YubiKey.

That binding persists across the employment lifecycle and helps detect substitution attempts, credential handoff, and proxy access. It supports automated rechecks for employment status, address, criminal record, and licence validity.

**Enforced system access** 

Access to cloud environments, SaaS tools, code repositories, and internal systems is gated on verified identity, not transferable credentials.

Zero-trust login is handled through OIDC and decentralised identity primitives designed to make access non-transferable. If identity cannot be confirmed, access is not granted.

## Use cases

Protect sensitive systems before a fake hire gets inside.

**Remote developers** \
Confirm the developer accessing your repositories, cloud infrastructure, and production systems is the person you hired.

**Contractors and agencies** \
Extend identity binding to contractors, outsourced engineers, and third-party technical teams, with business identity and director checks where required.

**Privileged access** \
Require proof of the verified person before granting access to administrator tools, deployment pipelines, production systems, or customer data.

**Offboarding** \
Revoke identity-bound access in real time when an employee or contractor leaves, reducing lingering tokens and manual offboarding gaps.

## **How It Works**

A trusted chain from onboarding to every login.

1. Verify the individual The employee or contractor completes NFC e-Passport chip verification against government-issued cryptographic certificates, biometric and liveness checks matched against the verified document, and Right to Work or employment eligibility. Supporting checks cover criminal background, address verification via utility bill and bank statement, SIM swap detection, email and mobile number verification, and qualifications and social presence checks. Document validation can run through providers including LexisNexis and Onfido.
2. Bind them to your organisation Nuggets creates a cryptographically verifiable relationship between the verified individual, their role, and the business they represent.
3. Issue a reusable credential Verified status becomes a portable, holder-bound verifiable credential that travels with the individual. Repeat hires and contractor renewals can validate against the existing credential without re-running every underlying check from scratch.
4. Connect access Integrate with HR, onboarding, HRIS, ATS, IAM, CIAM, zero-trust access, and SaaS using APIs, mobile SDKs, OIDC, W3C Decentralised Identifiers, and Verifiable Credentials.
5. Enforce and revoke Access is granted only when the verified person can prove control. When the working relationship ends, identity-bound access can be revoked across connected systems.

## **Why Nuggets**

Background screening, MFA, and IAM each answer one question well. None of them, on their own, prove the person accessing your systems right now is the verified employee or contractor you hired.

Background checks Did this person pass screening at the point of hire?

MFA and passkeys Does this session have the credential or device?

Nuggets KYE Is this the verified person, acting for this organisation, with authority to access this system right now?

## Trust stack

KYE is one layer in a five-part trust stack.

A verified individual, acting through a verified employment relationship, on a verified device, with verified AI agents, creates a complete accountability chain across every layer of your environment.

| **Framework**      | **Verifies**                                                                         | **Covers**                |
| :----------------- | :----------------------------------------------------------------------------------- | :------------------------ |
| Know Your Customer | Individual identity. Documents, biometrics, liveness.                                | Humans                    |
| Know Your Business | Legal entity. Individual cryptographically bound to organisation.                    | Organisations             |
| Know Your Employee | Employment relationship. Individual confirmed as authorised to act for the business. | Employees and contractors |
| Know Your Agent    | AI agent identity. Agent verified as controlled by an accountable organisation.      | Autonomous AI agents      |
| Know Your Machine  | Device integrity. Hardware bound to a verified business entity.                      | Devices and hardware      |

## Deployment

Start with a portal. Scale with APIs.

**Standalone onboarding portal** \
Verify remote employees and contractors without a heavy integration project. Ideal for teams that need to close the hiring fraud gap fast.

**Enterprise SDK and API Mobile** \
SDK for iOS and Android, embedded inside existing HR, onboarding, HRIS, and ATS workflows. Modular components support IDV-only or full lifecycle verification. Skinnable flows operate within your UX and branding.

**Same evidence layer** \
All configurations operate on the same decentralised trust infrastructure and produce the same cryptographic audit evidence. Multi-cloud and hybrid deployment supported. No centralised identity document warehousing required.

**Works alongside your stack** \
Okta, Microsoft Entra, HRIS and ATS platforms, LexisNexis, Onfido, Twingate, AWS, GCP, Azure, Cloudflare, OIDC applications, and zero-trust access tools.

## Business outcomes

Reduce remote-hiring risk without slowing down hiring.

**Stop substitute workers** \
Make it materially harder for someone else to take over the identity, credentials, laptop, or session of the person you hired.

**Reduce credential sharing** \
Gate access on verified identity, not on passwords, passkeys, YubiKeys, or company laptops that can be shared or handed off.

**Protect code and cloud access** \
Require proof of the verified person before access to repositories, production systems, and administrator tools is granted.

**Create cryptographic audit evidence** \
Tamper-evident compliance artifacts replace fragmented document-based records and support supervisory review.

**Speed up repeat verification** \
Reusable credentials for contractors, multi-role workers, and regulated rechecks avoid re-running every underlying check from scratch.

**Clean offboarding** \
Identity revocation flows into connected systems so access does not persist after the working relationship ends.

## **Compliance**

Built for regulated employment environments.

Compliance is produced through cryptographic proof and structured evidence, not through document accumulation. Encrypted, tamper-evident audit artifacts support supervisory review without requiring identity document warehouses inside HR.

* PCI DSS and ISO 27001 certified
* UK Digital Identity and Attributes Trust Framework alignment
* EU AI Act deployer obligations for high-risk AI systems, including human oversight, monitoring, log retention, and workplace notification where applicable
* DORA accountability requirements for financial services
* FCA Senior Managers Regime accountability chain preservation when actions are delegated
* NIS2 control evidence and continuous proof-of-control support
* GDPR and privacy-by-design architecture throughout

## **Architecture & Technical Components**

* NFC e-Passport chip verification against government-issued cryptographic certificates
* Biometric and liveness detection
* W3C Decentralised Identifiers (DIDs) for agent and employee identity
* Verifiable Credentials (employment eligibility and identity status)
* Holder binding and cryptographic proof validation
* Encrypted, tamper-evident compliance artifacts ("Auditable Nuggets")
* OIDC integration for non-transferable system login
* Real-time identity revocation on offboarding
* Proof validation APIs

Contractors are supported with an extended verification set covering Know Your Business (KYB), director identity, and business communications.

## FAQ

\*\*Does KYE replace our existing background check provider? \*\*\
No. Nuggets works alongside existing verification providers including LexisNexis and Onfido. KYE adds cryptographic binding, portable credentials, continuous re-verification, and access enforcement on top of the underlying checks.

\*\*Does this replace Okta, Microsoft Entra, or our IAM stack? \*\*\
No. KYE augments existing IAM and CIAM systems with credential-based proof, lifecycle assurance, and continuous identity binding. It does not require replacement of your current stack.

\*\*Can contractors use the same flow as full-time employees? \*\*\
Yes. Contractors can use an extended verification set covering business identity, director identity, and business communications in addition to the standard employee checks.

**What happens when an employee leaves?**\
Identity is revoked in real time at offboarding. Access tied to that verified identity can be removed across connected systems.

**Can KYE stop fake remote worker schemes?**\
KYE is designed for this class of risk. It addresses the core mechanics: fabricated identity documents, substitute workers, credential handoff, laptop and session sharing, proxy access, unverified contractors, and access persisting beyond offboarding.

Its strength is binding the verified person to the working relationship and to system access. It should be deployed as a control to reduce and block this class of risk, not as a guarantee against every possible threat.

\*\*Can KYE stop overemployment? \*\*\
It can prove the person accessing your systems is the verified worker you onboarded, which closes substitute-worker and proxy-access vectors.

It does not, by itself, prove that the same person is not also working elsewhere. That requires additional policy controls, attestations, or employment-status checks layered on top.

\*\*How is data handled and stored? \*\*\
Nuggets uses W3C Decentralised Identifiers, holder-bound Verifiable Credentials, and encrypted, tamper-evident compliance artifacts. There is no centralised warehouse of identity documents. The architecture is privacy-by-design throughout.

## Hiring remote developers? Verify who gets access.

Nuggets KYE verifies employees and contractors, binds identity to the working relationship, and enforces access based on proof of the verified person.

Want to discuss how KYE fits your workforce verification and access control requirements? [Talk to us](https://www.nuggets.life/docs/platform/contact-us) about your environment.
