
This FAQ is maintained as questions arrive. If your question is not answered here, submit it through the support portal at portal.cerebrum.com/support and we will add it.
Why is this order stuck in Pending? It is not stuck. Orders that do not clear auto-approve hold a Pending status and Pending score until a CRA reviewer resolves them. Cerebrum does not assign a final score on a flagged order. See Decision Ownership in the vID Workflow.
Can Cerebrum complete or score an order for us? No. Cerebrum is not a consumer reporting agency and does not render the final determination on whether an applicant's identity is verified. We will explain what any alert means and what the system observed, but the decision is yours.
Has something changed — we seem to be reviewing more orders than before. The auto-approve criteria are configurable at the account and package level. An increase in review volume usually traces to a configuration change, a change in applicant population, or an integration change on your side. Contact your Cerebrum representative and we can review your settings and recent flag distribution with you.
Do we reorder or complete it manually? Depends on the alert. See the vID Alert-to-Action Matrix. In general: reorder when the submission is unusable and the applicant can reasonably try again; complete when your reviewer is satisfied despite the alert; escalate when the alert is substantive.
Who sends the reorder — you or us? You. Use Send Reorder Invite at the top of the order in Cortex. Reorders are a CRA action.
The overall fraud check shows an alert but everything below it looks fine. The overall fraud check is a roll-up. It reflects any subordinate check that fired. Open the order and identify which specific check raised the alert, then act on that.
The order says "alerts found" but the checks are all green. Check whether the applicant entered ID data manually. After two failed scan attempts, applicants are routed to manual entry, and orders completed that way are flagged because the automated checks could not run against extracted document data — even though nothing appears red.
What does "verification data is missing" mean? Data could not be extracted from the ID scan, so the verification checks did not run. This is usually image quality, not fraud.
Why do applicants on corporate laptops keep getting flagged? Corporate VPNs and proxies trigger the IP address check. Ask the applicant to complete verification from a personal device on a home network, or disable IP address checks at the package level if the flags are not useful to your workflow. Corporate proxy connections will be confirmed and available under the IP address check details in Cortex.
Why does an expired ID go to manual review instead of failing? So that your team retains the decision. Expiry checks route to review rather than producing an automatic outcome. Whether you accept a recently expired document is a policy question, and one worth confirming with your legal counsel where the verification supports a regulated process.
Will vID accept a temporary license? Temporary and interim credentials generally lack the security features and machine-readable data the checks rely on, so they typically cannot be verified through the standard flow. Your policy determines whether to accept one with a documented exception, hold the order, or request an alternative document.
What about tribal identification? Tribal IDs are not uniformly machine-readable and are not covered by AAMVA. Confirmation through the issuing tribal registrar is one path. Because acceptance standards here carry legal implications, we recommend establishing your policy with your legal counsel.
An applicant cannot show their full face for religious or medical reasons. Packages can be configured to bypass liveness where a client's requirements permit, and alternative paths are available. Contact your Cerebrum representative. Accommodation obligations vary by jurisdiction and employment context, so we recommend determining your approach with your legal counsel.
Can we reduce how many orders reach manual review? Yes. Check depth and strictness, IP address checks, and name variation checks are all adjustable at the account and package level. See the Partner Admin Guide.
What is the difference between a VID- and an ORD- identifier?VID- is the invitation. ORD- is the order created when the applicant submits. An invitation that has not been completed has no associated order.
How long is an invitation valid? The default is 30 days. This is adjustable at the package level via the Expiration Time setting.
Can we extend the expiration window? Yes, at the package level. Contact your Cerebrum representative.
An applicant says their invitation is expired. What now? CRA can self-service reissue from Cognition
What is a resubmission link? It is the new verification link generated when you issue a reorder. There is nothing structurally different about it — the applicant completes the same flow.
Can we get a general link that is not tied to a specific applicant? Yes. A package can expose a persistent verification link at an organization-specific address in the form yourorganization.vid.page. Contact your Cerebrum representative to have one enabled for a client. Note that a demo or test organization link will not route submissions to a client account — the client must be onboarded first.
Why did the invitation go straight from Sent to Complete without showing Accepted? The Accepted status is set when the applicant opens the invitation and begins the flow. Refer to docs.cerebrum.com/reference for current status and event behavior, and report any inconsistency you can reproduce through the support portal with the invite ID.
Our new admin user hit a 404 after creating their account. Expected. New accounts are provisioned with base user permissions and cannot reach the admin platforms, so the final redirect has nowhere to go. Once the user confirms they reached the 404, their permissions are elevated and they can log in.
An admin user still sees a 404 after their permissions were elevated. They are most likely landing in the applicant verification flow rather than the admin platform. Ask them to close all Cerebrum tabs and navigate directly to cortex.cerebrum.com.
A reviewer cannot see an order they should have access to. Confirm they have All Organizations selected in Cortex. Scope is the most common cause.
How do we add or remove users? Users create their own accounts; permissions are then assigned. See the Partner Admin Guide. To remove a user, please submit a request via the support portal.
Can we get a list of everyone with access to our account? Yes — request it through the support portal.
What is your data retention policy? Standard verification data follows a seven-year default period aligned with FCRA retention requirements. Biometric facial vectors are used only to produce the pass/fail result and are deleted immediately afterward—within approximately 10 seconds of verification. Identity documents and applicant images may be retained for statutory and compliance purposes and are subject to the applicable privacy policy. Client-specific retention terms can be configured. Confirm the terms applicable to your account with your Cerebrum representative and review them with your legal counsel.
What happens to the applicant's selfie? It is converted to a mathematical facial vector used to determine the pass/fail comparison result. The vector is deleted immediately after use.
What does the applicant consent to? Applicants sign a biometric disclosure during the vID flow describing how the selfie is used, what is retained, and for how long. The disclosure link can be shared with an applicant on request through your Cerebrum representative.
How do biometric privacy obligations apply to us? Biometric privacy laws vary significantly by state and impose obligations on the entities collecting and using biometric data. Your obligations depend on your role, your jurisdictions, and the terms of your agreements. This is a question for your legal counsel, and we recommend reviewing your channel partner agreement with them specifically on this point.
Who handles applicant disputes? The CRA, under its existing FCRA dispute process. Applicants do not hold accounts in the Cerebrum platform, and Cerebrum does not issue the consumer report. We will supply the underlying verification data needed to support a reinvestigation.
An applicant has requested a copy of their report. Provide it through your standard FCRA process. Nothing about the vID product or the Credential Wallet alters an applicant's right to a copy of their consumer report on request.
What is the Credential Wallet, and can applicants add their own documents to it? The Credential Wallet holds credentials captured during the vID flow. Applicants cannot upload credentials outside that flow. Any credential originating elsewhere must be added through a supported path — contact your Cerebrum representative to discuss a specific use case.
Does vID detect applicants using a fraudulent identity? That is what it is built for. Liveness confirms a real, live applicant is completing the flow; document checks evaluate the authenticity of the identity document; biometric comparison confirms the person matches the document. It is designed to surface identity fraud before it reaches a hiring decision.
Does it work the same way through our ATS or platform integration? Yes. The verification behavior is identical regardless of the ordering route. Integration determines how the order is placed and how results are delivered, not how verification is performed.
Can vID be used at stages other than pre-hire background screening? Yes. Verification can be run at interview scheduling, at equipment handoff, at onboarding, or at any other point where confirming identity is useful. Where an existing integration is scoped to the background check stage, additional stages are typically served by a separate ordering route. Contact your Cerebrum representative to scope a specific workflow.
Do you have success-rate or clearance statistics we can use with clients? Some product areas have sufficient volume to report on and some do not. Ask your Cerebrum representative for what is currently available rather than estimating — we would rather give you a defensible number than a plausible one.
What languages does the applicant flow support? English, Spanish, French, Russian, and Hindi, selected from the applicant's device settings and currently available through the mobile application experience. Additional languages can be added on request.
Where do we send issues? The support portal at portal.cerebrum.com/support. Sign in with your work email to see all of your open requests in one place.
What should we include? The Cortex order ID or invite ID, the applicant's email address where relevant, and a description of expected versus observed behavior. Screenshots help.
What are your response times? During business hours, a Cerebrum support team member will get back to you within 1-2 hours.
How do we know if there is a platform-wide issue? Check status.cerebrum.com before opening a ticket.
This FAQ is provided for operational reference and does not constitute legal advice. Where a question touches your obligations under the FCRA, biometric privacy law, or employment law, we recommend consulting your legal counsel.