Proofing happens at enrollment: validating government documents, comparing a live capture to a photo, checking authoritative records, or verifying organization membership. Standards like NIST SP 800-63A define assurance levels for how strong that evidence must be; higher-stakes access requires stronger proofing.
Key points
Risk-proportionate proofingAdministrative, financial, or regulated access needs stronger evidence than a community forum; over-proofing adds cost and exclusion without benefit.
One-time trust anchorEverything issued afterward inherits its strength — weak proofing cannot be repaired by strong authentication later.
Important limitationProofing establishes identity at enrollment, not intent afterward. A correctly proofed account can still be sold, shared, coerced, or later compromised through recovery or session weaknesses.