# Presence > Presence - adaptive human verification layer. Presence evaluates behavior, device trust and liveness, stepping up verification only when needed before sensitive actions execute. Presence is built by Decionis. Sensitive actions are gated on a verified, present human before they execute, and every decision seals a signed record that can be verified independently of the vendor. Presence is not identity onboarding, background checking, facial recognition on its own, post-event deepfake scoring, another meeting-security tool, or a general fraud-scoring API. It is a check placed at the point where trust becomes irreversible, combining device proof, presence proof and authority proof into a single Verdict with a signed Presence Record. Presence's own name for the category is Human Presence Infrastructure; the Decionis platform calls the same layer proof-of-human infrastructure. Canonical product URL: https://presence.decionis.com/. Parent platform: https://decionis.com (Decionis decides whether the action may execute; Presence verifies that the authorized person is really present for it). Production enforcement is sales-assisted; the demo and the sandbox need no signup. ## Product - [Live demo](https://presence.decionis.com/demo): Run the real engine in the browser and download the signed Presence Record it produces. No signup. - [Sandbox](https://presence.decionis.com/sandbox): Create an isolated sandbox and run deterministic allow, block, and escalate fixtures in Shadow Mode. - [Security review](https://presence.decionis.com/security): What leaves the browser, what happens when Presence fails, and who can see what. - [Connectors](https://presence.decionis.com/connectors): Meeting, identity, and enterprise connectors with their readiness stated. - [Reference](https://presence.decionis.com/reference): Every machine document on this site, and the zero-human onboarding sequence. ## Why identity is no longer enough (https://presence.decionis.com/why) - [Authentication proves a credential. Presence proves participation.](https://presence.decionis.com/why/authentication-is-not-presence): A passkey proves a trusted authenticator was used. It does not prove the authorized person is participating in this specific action, right now. - [Approval chains assume the people in them are real](https://presence.decionis.com/why/deepfakes-break-approval-chains): A finance worker paid out $25 million after a video call with his CFO and colleagues. Every participant was synthetic. Nothing about the call was checked, because approval chains verify authority, not presence. - [A detection score after the wire has moved is an incident report](https://presence.decionis.com/why/detection-after-execution-is-too-late): Scoring recordings after the fact tells you what happened. It cannot stop it. The control has to sit before the irreversible step. - [A pre-execution presence check for consequential actions](https://presence.decionis.com/why/human-presence-infrastructure): Human Presence Infrastructure verifies that the real, authorized person is actively participating when a consequential action is requested — and produces evidence downstream systems can enforce and independently verify. - [The analysis runs where the person is](https://presence.decionis.com/why/on-device-verification): No frames, no audio, no face mesh leave the device. What crosses the wire are floating-point scores and hardware booleans — which is why this survives a privacy review. ## How a presence check works (https://presence.decionis.com/how-it-works) - [Proof of Device](https://presence.decionis.com/how-it-works/device-proof): A passkey assertion, verified server-side, whose challenge commits to the exact action being approved. - [Proof of Presence](https://presence.decionis.com/how-it-works/presence-proof): Pulse under the skin, a randomized screen-reflection challenge, and lip–voice alignment — scored on the weakest signal, not the average. - [Proof of Authority](https://presence.decionis.com/how-it-works/authority-proof): Policy turns evidence into one of four verdicts, scaled to what the action is worth and who is asking. - [Action binding](https://presence.decionis.com/how-it-works/action-binding): The session nonce commits to a hash of the action context, and the server re-computes that hash at decision time. - [Signed records](https://presence.decionis.com/how-it-works/signed-records): Every decision — including the ones that were allowed — is sealed with an Ed25519 signature over its canonical form, chained to the record before it. - [Failure behaviour](https://presence.decionis.com/how-it-works/failure-behaviour): The decision call is one HTTP request you time out on like any dependency. Telemetry is sideband, and one request returns every surface to watch-only. ## Verify at the moment trust becomes irreversible (https://presence.decionis.com/use-cases) - [Wire transfer human verification](https://presence.decionis.com/use-cases/wire-transfer-human-verification): Check the person approving the transfer — live, on a trusted device, bound to this amount and beneficiary — before the payment commits. - [Vendor bank-detail change](https://presence.decionis.com/use-cases/vendor-bank-detail-change): The change itself is the consequential action. Verify the person making it before the new account is saved, not when the first payment fails. - [Executive video-call verification](https://presence.decionis.com/use-cases/executive-video-call-verification): Verify the instruction-giver is really on the call — before what they asked for becomes actionable. - [CEO impersonation fraud](https://presence.decionis.com/use-cases/ceo-impersonation-fraud): The instruction arrives on a convincing call; the loss executes as a legitimate payment. Verify the executive on the call, and the human behind the payment, before it commits. - [Deepfake meeting verification](https://presence.decionis.com/use-cases/deepfake-meeting-verification): Admission is the moment of control. Verify the person behind each participant before the room admits them — a synthetic feed fails the check even when nobody could spot it. - [Privileged access verification](https://presence.decionis.com/use-cases/privileged-access-verification): Help-desk social engineering works because the reset path trusts a voice. Put a presence check in front of the reset, the grant and the enrollment — before the change applies. - [Treasury payment approval](https://presence.decionis.com/use-cases/treasury-payment-approval): Start in watch-only to measure what would have been challenged, then enforce on the band of transactions that justify the friction. - [Board meeting verification](https://presence.decionis.com/use-cases/board-meeting-verification): Verify who is actually present before a resolution is recorded, using the meeting platform's own participant events. - [Payroll change](https://presence.decionis.com/use-cases/payroll-change): Payroll diversion is a bank-detail change with a payday deadline. The check belongs on the change, before the run. - [High-value refund](https://presence.decionis.com/use-cases/high-value-refund): Refund abuse runs through legitimate accounts. Verify the operator authorizing an unusual refund before the money leaves. - [Remote employee verification](https://presence.decionis.com/use-cases/remote-employee-verification): Re-establish presence at moments that matter — a privileged grant, a first payment, an equipment release — rather than once at onboarding. - [AI agent human escalation](https://presence.decionis.com/use-cases/ai-agent-human-escalation): When an autonomous workflow hands a decision to a person, verify that a person actually took it — and record that they did. ## Where the consequential action begins (https://presence.decionis.com/surfaces) - [Web](https://presence.decionis.com/surfaces/web): The direct path: the web SDK runs the checks in your page and your server calls the decision API before the action commits. - [API](https://presence.decionis.com/surfaces/api): One authenticated request returns a verdict and a verification bundle. Signals can come from our SDK or from your own capture path. - [Microsoft Teams](https://presence.decionis.com/surfaces/microsoft-teams): Your Microsoft administrator approves Presence once, and participants joining a call are verified from then on. - [Google Meet](https://presence.decionis.com/surfaces/google-meet): Pilot-ready browser-extension coverage for the consenting user's local Meet self-view, with on-device signals and server-controlled escalation. - [Zoom](https://presence.decionis.com/surfaces/zoom): Verify participants using Zoom's own webhook events, installed from your Zoom account. - [Webex](https://presence.decionis.com/surfaces/webex): Organization-owned participant webhooks drive verification for Webex meetings. - [Slack](https://presence.decionis.com/surfaces/slack): The case, the evidence, and the approve or deny actions arrive in a Slack channel your security team already watches. - [Okta](https://presence.decionis.com/surfaces/okta): An inline hook on sensitive identity actions — password reset, privilege grant, factor enrollment — that acts on the verdict before the change applies. - [SAP S/4HANA](https://presence.decionis.com/surfaces/sap): A verification step inside an existing SAP workflow, called before the release commits. - [Workday](https://presence.decionis.com/surfaces/workday): Planned. There is no Workday connector today — the use case is reachable through the API or the web SDK in the meantime. - [Treasury systems](https://presence.decionis.com/surfaces/treasury): Planned. Treasury workflows are supported today through the API and the web SDK; a packaged TMS connector does not exist. ## Check it rather than believe it (https://presence.decionis.com/proof) - [Evidence index](https://presence.decionis.com/proof/evidence-index): Every artifact on this site that a skeptic can fetch, run, or reproduce. - [Verify a record](https://presence.decionis.com/proof/verify-a-record): Download the verification bundle from any decision and check it offline against our published key. Nothing is sent to us. - [Signing keys](https://presence.decionis.com/proof/signing-keys): Published unauthenticated as JWKS and as SPKI PEM, including retired keys, so records sealed before a rotation stay verifiable. - [Example Presence Record](https://presence.decionis.com/proof/example-presence-record): Who, what, when, why, device, challenge, signature — the sealed answers, plus where to fetch the key and the verifier that check them. - [Privacy model](https://presence.decionis.com/proof/privacy-model): Numbers, never media. No endpoint accepts frames or audio, so this is not a policy that could be quietly relaxed. - [Security review](https://presence.decionis.com/proof/security-review): The questions asked in every review, answered in public — including the ones where the answer is no. - [Threat model](https://presence.decionis.com/proof/threat-model): What is defended, what is mitigated, and what is explicitly out of reach — including a compromised operating system. - [Shadow-mode methodology](https://presence.decionis.com/proof/shadow-mode-methodology): In watch-only, the true verdict is still computed and sealed — only the answer given to the caller is softened. That is what makes it a measurement. ## Presence developer docs (https://presence.decionis.com/developers) - [Quickstart](https://presence.decionis.com/developers/quickstart): Run a deterministic sandbox decision and inspect its signed record. - [API reference](https://presence.decionis.com/developers/api): Sessions, decisions, challenges, dossiers, and enforcement outcomes. - [Web SDK](https://presence.decionis.com/developers/web-sdk): Intent display, WebAuthn, camera evidence, and capture-agent attestation. - [Supabase Auth Hooks](https://presence.decionis.com/developers/auth): Fail-closed sign-up verification and JWT assurance claims for Supabase Auth and Postgres RLS. - [Vercel integration](https://presence.decionis.com/developers/vercel): A connectable-account OAuth installation plus fail-closed enforcement for consequential writes — as Edge Middleware or per-route withPresence wrappers. - [Kong Gateway plugin](https://presence.decionis.com/developers/kong): A native Lua plugin that verifies Presence at the gateway, mints browser-safe sessions, and fails closed. - [Envoy Gateway Wasm filter](https://presence.decionis.com/developers/envoy-gateway): A proxy-wasm filter loaded by an EnvoyExtensionPolicy that gates protected routes on a verified Presence proof or session and fails closed, with no application changes. - [Postman collection](https://presence.decionis.com/developers/postman): A generated collection for sessions, decisions, dossiers, accounts, and deterministic sandbox scenarios. - [Webhooks](https://presence.decionis.com/developers/webhooks): Signed delivery for every decision, including shadow-mode results. - [Policy signals](https://presence.decionis.com/developers/policy-signals): Thresholds, evidence quality, and the distinction between measured and unavailable. - [Test vectors](https://presence.decionis.com/developers/test-vectors): Pinned canonical bytes and signatures for cross-language verification. - [Offline verifier](https://presence.decionis.com/developers/offline-verifier): Dependency-free Ed25519 and chain-hash verification with stable exit codes. ## Sibling properties Every link below resolved on 2026-09-13. - [Decionis](https://decionis.com): the Execution Authority platform Presence hands its signal to — policy verdicts, execution grants, signed Decision Dossiers. Machine summary: https://decionis.com/llms.txt. - [Proof-of-human infrastructure on the platform](https://decionis.com/presence): the platform's page for this layer. - [Agent-Safe Pipeline](https://github.com/decionis/agent-safe-pipeline): the open reference implementation of the execution boundary; its Presence examples are runnable code for resolving an escalated agent action with a Presence Check. - [Banking Execution Authority Profile](https://banking.decionis.com): the platform's banking profile — a disbursement, a payment run or a limit increase, and who signs it. Machine summary: https://banking.decionis.com/llms.txt. - [Commerce Gate](https://commerce.decionis.com): the platform's commerce property — prices, orders, refunds and returns checked against policy before acting. Machine summary: https://commerce.decionis.com/llms.txt. ## About this site, for machines The artifact is always a Presence Record, the operation a Presence Check, and the verdicts are AUTHORIZED, BLOCKED, ESCALATE, RESTRAIN. No latency or accuracy figure is published anywhere on this site or claimable from it. The machine-actionable inventories — API operations, verification keys, packages, MCP surfaces, the onboarding sequence and the routing rules — are in https://presence.decionis.com/llms-full.txt; the AI-focused page subset is https://presence.decionis.com/sitemap-ai.xml.