What a network is
A network is a cluster of subjects (vendor users, vendor businesses, or transaction parties) connected through one or more shared signals. Didit builds networks continuously as verification sessions, business sessions, and transactions complete, clustering organization-wide across every application in your organization so a fraud ring that touches two of your products still surfaces as one network. Each application only sees the networks that include at least one of its own subjects.Clustering runs on production data only. Sandbox applications are excluded entirely, sandbox sessions never create or join a network.
Signal types
A network forms when two or more subjects match on any of these signals:Exact device match
The same device fingerprint appears across sessions.
Similar device match
Device fingerprints similar enough to indicate the same physical device with minor variation.
Same IP address
Sessions or transactions originating from the same IP address.
Same physical address
Proof-of-address or registry data resolving to the same address.
Similar selfie backgrounds
Liveness captures sharing a visually similar background, a signal of a single operator running multiple sessions from one location.
Similar POA documents
Proof-of-address documents similar enough to indicate template reuse or a shared source document.
Signal values are never stored or displayed in the clear. Every signal except the selfie-background and face-similarity signals is identified by a keyed hash of its normalized value, exact matches link subjects without Didit (or you) ever seeing the underlying device ID, IP, document number, phone, or email again.
Viewing a network
The Networks list is a table of every network visible to your application: network id, name, status, risk, the patterns and signals detected, and first/last activity, with the same status, signal, pattern, and risk-band filters as the API, plus free-text search by network name, member name, or network id. Opening a network gives you four ways to explore it:Graph
Subject and signal nodes connected by edges. Focus on one applicant and bound the view to 1, 2, or 3 hops to isolate their immediate connections instead of the whole network.
Table
Every member as a row, with outcome status, risk, tags, and signal coverage, for scanning or exporting a large network.
Map
Geographic points where members’ addresses and locations converge, useful for spotting a ring anchored on one address or city.
Timeline
Chronological history of the network: when it was first detected, when each signal was observed, and every status change with its reason.
Lifecycle
A network moves through exactly four statuses:
Every status change is recorded with a reason and the acting analyst, forming the network’s audit trail alongside its signal and detection history.
Network status describes the investigation, not any one member. Each member also carries its own outcome status inside the network (
Approved, In review, Declined, Not completed), which is that applicant’s own verification decision. A network can be Active while individual members are already Approved or Declined.Acting on a network
From a network’s detail page you can:- Create a case to hand the network to your compliance team for a formal investigation, anchored to the network rather than a single subject.
- Add to blocklist a member’s identity, or the signal itself, so future sessions matching it are automatically declined.
- Change status to move the network to In review, Resolved, or Dismissed, with a required reason.
- Dismiss a network in one step when it is clearly not fraud, this also closes out an active review if one is open.
Related pages
List networks
Retrieve networks for your organization through the API.
Network membership lookup
Look up which networks a session, user, business, or transaction belongs to.
Blocklist users
How blocklisting a document, face, phone, or email affects future sessions.
Cases
Investigate a network case through to resolution.