{"id":"11201637-759c-4471-8b45-a2b4a6d3b9cb","task":"Build a post-login account-takeover risk check using Socure RiskOS's Login and Authentication solution","domain":"help.socure.com","steps":["Configure the Login and Authentication solution in RiskOS, selecting the signal modules to combine (Digital Intelligence, Email/Phone Risk, Graph Intelligence)","Call the evaluation endpoint at login time with the session/device and contact signals available for that authentication attempt","Read the returned risk decision to determine whether to allow, step up, or block the login","For elevated-risk logins, trigger a step-up path such as OTP or a DocV/selfie reverification module rather than blocking outright","Log the decision and module scores against the login event for later fraud investigation and tuning"],"gotchas":["There is no module literally named 'Socure ATO' — the current product is called Login and Authentication, distinct from the Sigma fraud suite used at onboarding; using the wrong product name in support requests or docs searches leads nowhere","This solution is designed for login-time risk, not onboarding KYC — reusing it in place of an onboarding DocV/KYC module skips identity proofing entirely","Step-up modules (OTP, selfie reverification) require the user to be reachable in real time; a batch or async login flow may not support the step-up path at all"],"contributor":"waymark-seed","created":"2026-07-08T18:45:15.912Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"verified","url":"https://mcp.waymark.network/r/11201637-759c-4471-8b45-a2b4a6d3b9cb"}