Sending Certivus Pass invites
In brief: Step-by-step: send, resend, cancel, and read the recent-invites list.
The Pass invite is the firm-side action that asks a client to verify their identity via Certivus Pass, our reusable consumer credential. The same client can reuse the result with any UK firm that accepts Certivus.
Where you do it
Open any client profile. On the Overview you'll see a primary-tinted "Send a Certivus Pass invite (beta)" card, before any verification tabs. The standard one-off route remains available when a reusable Pass is not the right fit.
How to send an invite
- Click Send Certivus Pass invite.
- The dialog prefills the client's email, name, and phone from the CRM record. Edit if needed.
- Pick the verification level:
- Standard: document + selfie + AML screen.
- Enhanced: Standard + 12-month address history + ongoing monitoring.
- Corporate: Enhanced + director / UBO checks.
- Optional: add a matter reference (your internal tracking ID) and a purpose (shown to the client so they know why you're asking).
- Click Send invite.
The client receives an email within seconds with a one-click verification link. The whole flow takes them about 3 minutes.
What happens next
The card collapses into a confirmation showing:
- The verification URL: copy it if you'd rather share via WhatsApp / SMS / face-to-face.
- Status: "email sent" or, if delivery failed, "email failed" with a hint to copy the link instead.
Below that, you'll see a Recent invites list with every Pass invite you've sent to this client. Each row shows:
| Field | What it means |
|---|---|
| Status badge | Pending / Verified / Declined / Expired |
| Tier | Standard / Enhanced / Corporate |
| Sent | Relative time ("sent 2 hours ago") |
| Pass number | CERT-YYYY-XXXXX, shown once the client completes |
| Confidence | The GPG 45 confidence the Pass reached |
| Matter ref | Your internal reference, if you set one |
Resending or cancelling
For any pending invite, two extra icons appear next to Copy + Open:
- Resend (paper-plane icon): fires the email again with a fresh delivery timestamp. The original token is reused, so the client's link doesn't change.
- Cancel (X icon, red-tinted): opens a confirmation, then invalidates the link immediately. If the client tries to use it, they'll see a "declined" message. The audit log records the cancellation.
You can't resend or cancel an already-completed invite; at that point the firm has the share and the client has (optionally) saved the Pass.
When the client finishes
The moment the client completes their Pass verification:
- The firm gets a share: the verified identity (and optional AML data) becomes visible to staff.
- Audit log entry:
Certivus Pass shared with firmlands on the client's compliance file with the Pass number, tier, and GPG 45 profile. - Recent invites list updates: the row flips to Verified with the Pass number visible.
What gets shared with the firm by default
For the initiating firm (you, the one that sent the invite), the default selective-disclosure is:
- ✅ Identity (name, DOB, document details)
- ✅ Sanctions check result
- ✅ PEP check result
- ✅ Adverse media check result
- ❌ Address (deferred; the client can re-share with explicit consent if you need address-of-record proof)
If a client later shares their Pass with another firm, that firm goes through a fresh consent capture; they don't piggyback on your share.
Limits + edge cases
- Invites expire after 30 days. Past expiry, the recent-invites badge flips to "Expired" and resend stops working. Send a fresh invite instead.
- Email delivery isn't guaranteed. Domain reputation, recipient spam filters, etc. If delivery fails, copy the link from the card and share by other means.
- Wrong email? Cancel the invite and send a new one with the correct address. The cancellation lands in the audit log.
When NOT to use Pass
The standard one-off verification route is still the right call when:
- The client refuses to consent to a reusable credential.
- You need a one-off check with no future portability (the legacy flow doesn't issue a Pass; results stay scoped to this firm).
- The client doesn't have an email address you can use (Pass is email-first).
The Pass card and the standard one-off route co-exist; firms can use either on a case-by-case basis.
Related help articles
- What is Certivus Pass? (the why and how, for context).
- Audit log: filter by "Certivus Pass" to see every Pass event across all your clients.
Didn't find what you needed?
Contact support