Identity Assurance Level (IAL)
NIST 800-63A levels describing identity proofing strength. IAL1: self-asserted. IAL2: remote or in-person verification with evidence. IAL3: in-person verification by a trained agent.
IAL is about proofing, not login: it answers "how sure are we this account belongs to a real, specific person" rather than "how strongly did they authenticate". Conflating it with AAL is the common mistake, and it produces systems with hardware keys protecting accounts that were opened with an unverified email. Regulated onboarding, benefits programs, and anything with fraud exposure need both levels stated separately.
See also: AAL, NIST 800-63, identity verification, identity verification vendors
Related on Start with Identity
- GlossaryAccount Recovery
The process by which a user regains access after losing their authenticator: a lost device, a forgotten password, or a revoked credential. It is a parallel auth
- GlossaryCIAM
Customer Identity and Access Management. The identity stack for end users of a product, distinct from workforce IAM. CIAM optimizes for self-service signup, con
- BlogHow to vet a national digital ID before you build KYC on it
Not every national ID is equally trustworthy or equally easy to verify. A practical seven-point checklist for evaluating a country's digital ID before you wire
- GlossaryKYC
Know Your Customer. Regulatory obligations to identify and verify the identity of customers, primarily in financial services. KYC is a workflow built on top of
- ArticleIdentity for Government: National eIDs, Assurance Levels, and Access
How identity works in the public sector: national eID schemes and citizen login, identity assurance levels under NIST 800-63 and eIDAS, workforce credentials li
- BlogMore than 16,000 Supabase databases were readable by anyone because row-level security was missing
UpGuard found over 16,000 Supabase databases exposing readable tables with personal data, plaintext passwords and authentication tokens, caused by missing or in