Enterprise identity operations
The next enterprise breach
starts with a phone call.
Fctr verifies callers—both ways.
Helpdesks verify employees before sensitive actions. Employees verify callers claiming to be IT or support before following sensitive instructions. Fctr uses existing organization-managed factors and connects verification, live identity context, policy-authorized actions, and audit evidence in one governed workspace.
AI deepfakes and spoofed numbers make vishing more convincing.
A cloned voice or video is not enough to pass verification. Fctr verifies callers through your organization's supported enrolled factors—including biometric-protected approvals where enabled.
Verification is only the first step.
Fctr connects helpdesk identity verification, live Entra ID or Okta context, policy-authorized actions, and PII-masked audit evidence in one support workspace.
-
01
Directory lookupAUTHORITATIVE DIRECTORY
Confirm an active employee record and display live profile details.
-
02
Factor verificationORGANIZATION-MANAGED FACTOR
Verify the caller through an enrolled factor managed by the organization.
-
03
Action authorizationONE TARGET · ONE ACTION
Keep sensitive actions unavailable until verification succeeds and role and policy permit them.
-
04
Audit recordAUDIT-READY EVIDENCE
Record a PII-masked audit trail of the verification, authorized action, and outcome.
Vishing works both ways. Verification should too.
One policy-backed engine enforces two-way verification using factors your organization already manages.
See how two-way caller verification worksVerify callers with factors the organization already manages.
Use passkeys, Microsoft Authenticator, Duo MFA, Okta Verify, and other configured methods without deploying another workforce authenticator.
Microsoft Authenticator
Uses an existing Microsoft Authenticator or Duo enrollment
Okta Identity CloudOkta Verify
Uses the employee’s current Okta enrollment
Verified ID + Face Check
Applied when organizational policy requires it
Live identity context. PII-masked evidence.
Fctr retrieves only what an active support session needs. PII-masked evidence connects the actor, factor, policy, action, and outcome. Review the public assurance overview.
Pricing for the way your team works.
Simple, predictable pricing for Fctr Portal, Fctr Verify, or both.
- ✓Enrolled-factor caller verification
- ✓Live identity data, groups, apps & devices
- ✓Account actions — reset, unlock, suspend
- ✓5-tier RBAC, PII shielding & audit evidence
- +Add Fctr Verify — $15,000/year per integration
- ✓Sandbox environment for setup and integration testing
- ✓Enrolled-factor verification in an existing support workflow
- ✓Predictable annual pricing—not user-based or per-verification
- +Additional integrations — $15,000/year each
Need pricing tailored to your organization? Talk to us.
Discuss Verify ↗For Verify deployments above 5,000 workforce identities or more complex platform requirements.
- ✓Custom connectors and implementation support
- ✓Dedicated deployment options
- ✓Premium support and SLA options
- ✓Complex multi-environment planning
The answers buyers need before a pilot.
Straight answers to the questions security and identity teams ask before connecting a workflow.
We already use Okta or Microsoft Entra ID. Why do we need Fctr?
Entra ID and Okta secure application access. Fctr binds a caller’s enrolled-factor proof to sensitive helpdesk actions: Portal gates authorized actions, while Verify returns the result to customer-deployed workflows.
How do employees verify callers claiming to be IT support?
The IT caller starts a request in Fctr Portal under the organization's verification policy. The employee independently opens Fctr in Teams or Outlook, checks the pending request, and selects the phrase the caller says. The employee never reads the choices back to the caller. This confirmation does not authorize a password reset or other support action.
Will caller verification slow down helpdesk SLAs?
Fctr Portal replaces console switching and manual handoffs with one workspace, reducing caller verification from about five minutes to under 60 seconds. Fctr Verify keeps agents in their existing queue.
Which existing MFA methods can Fctr use?
Fctr supports configured passkeys, Microsoft Authenticator Push and TOTP, Duo MFA for Entra ID, Okta Verify and number challenge, and Entra Verified ID with Face Check for higher-assurance step-up. Available methods depend on provider configuration and tenant policy.
What data does Fctr access from our identity provider?
Fctr uses scoped API access to retrieve identity context for the active support session without building a persistent workforce directory. Personal and recovery contact details are excluded from approved audit records. Organization-issued email addresses and UPNs are masked in human-readable audit labels; limited identifiers remain for security correlation and auditability.
How is Fctr deployed and integrated?
Organizations can connect a pilot to Okta or Entra ID with scoped tokens or OAuth 2.0, then use the browser-based, cloud-hosted Fctr Portal or Fctr Verify through a customer-deployed integration or the External Verification API. A sandbox demonstration requires no tenant access, and a connected pilot can be deployed in days; full rollout timing depends on integration, policy, and change-management requirements.
How are Fctr Portal and Fctr Verify priced?
Fctr Portal starts at $250 per agent per month with a five-agent minimum. Fctr Portal customers add Fctr Verify integrations for $15,000 per year each. Teams without Portal can license Fctr Verify for $35,000 per year for organizations with up to 5,000 workforce identities, with one integration included. Enterprise pricing starts at $50,000 per year for organizations with more than 5,000 workforce identities or advanced deployment requirements. Additional integrations are $15,000 per year each. Fctr Verify uses predictable annual pricing rather than per-user or per-verification pricing.
How does Fctr help protect against AI voice cloning and deepfake callers?
Fctr helps protect against AI voice cloning and deepfake vishing by requiring verification through supported organization-managed factors, rather than trusting a familiar voice or face. Biometric-protected approvals can be used where enabled by the provider and organization. Fctr Portal keeps supported sensitive actions unavailable until verification succeeds and role and policy permit them. Fctr verifies callers; it does not analyze audio or video to detect deepfakes.
See it first. Then try it in your environment.
See Fctr in action.
We’ll show caller verification, policy, and supported actions working together in Fctr’s sandbox. Want hands-on access? Connect your Entra ID or Okta tenant and use Fctr for 60 days.

