How to send a document with KBA authentication in the BoldSign mobile app?
Knowledge-Based Authentication (KBA) adds an extra layer of identity verification before a recipient can access and sign a document. When KBA is enabled, recipients must verify their identity by providing personal information and correctly answering security questions before they can view and sign the document.
KBA authentication is available only for recipients located in the United States.
How to enable KBA for a recipient in the mobile app?
- Tap the
+button from the bottom navigation bar on theDashboardscreen.
- Select
Create New Document.
- Upload the document that requires signatures.
- On the
Add Recipientscreen, enter the recipient’s name and email address.
Ensure that the recipient’s name matches their legal identity details. During KBA verification, BoldSign compares the entered name with the identity information provided by the recipient based on the configured Name-match tolerance level.
- Enable
Authenticationand choose theKBA Authenticationoption. - Tap
Edit settingsto review or modify the KBA settings.
KBA settings
- Default verification frequency: Determines how often the recipient must complete KBA verification when accessing the document.
- Number of retry attempts: Specifies the maximum number of verification attempts allowed before access is restricted.
- Name-match tolerance level: Controls how strictly the recipient’s name is matched against the identity information provided during verification.
- Tap
Confirmto save the KBA settings. - Tap
Configure fieldsbutton to continue the document creation process.
- Add form fields, review the document and tap
Sendbutton to send the document.
What happens after the document is sent?
- The recipient receives a signature request email.
- When the recipient opens the document, they are prompted to complete KBA verification.
- After successful verification, the recipient can access and sign the document.
- If the recipient exceeds the configured retry limit, access to the document is locked.
If a recipient is locked out after exceeding the allowed retry attempts, the sender can either reset the KBA authentication or remove authentication for that recipient.