Enterprise identity operations

The next enterprise breach
starts with a phone call.

Fctr verifies callers—both ways.

Helpdesks verify employees before sensitive actions. Employees verify callers claiming to be IT or support before following sensitive instructions. Fctr uses existing organization-managed factors and connects verification, live identity context, policy-authorized actions, and audit evidence in one governed workspace.

Verify callers in under 60 seconds No new authenticator to deploy
Works with Entra ID Okta Cisco Duo
Verification methods Passkeys Mobile push TOTP + SMS/Email OTP Entra Verified ID + Face Check
Support integrations ServiceNow Freshdesk Zendesk Slack Microsoft Teams

Verification is only the first step.

Fctr connects helpdesk identity verification, live Entra ID or Okta context, policy-authorized actions, and PII-masked audit evidence in one support workspace.

  1. 01
    Directory lookup

    Confirm an active employee record and display live profile details.

    AUTHORITATIVE DIRECTORY
  2. 02
    Factor verification

    Verify the caller through an enrolled factor managed by the organization.

    ORGANIZATION-MANAGED FACTOR
  3. 03
    Action authorization

    Keep sensitive actions unavailable until verification succeeds and role and policy permit them.

    ONE TARGET · ONE ACTION
  4. 04
    Audit record

    Record a PII-masked audit trail of the verification, authorized action, and outcome.

    AUDIT-READY EVIDENCE
No security questions No new authenticator No verification. No sensitive action. Supported actions without broad provider roles

Vishing works both ways. Verification should too.

One policy-backed engine enforces two-way verification using factors your organization already manages.

See how two-way caller verification works

Verify callers with factors the organization already manages.

Use passkeys, Microsoft Authenticator, Duo MFA, Okta Verify, and other configured methods without deploying another workforce authenticator.

EmployeeExisting enrolled factorAlready managed by the organization
Microsoft Entra ID
Core verification

Microsoft Authenticator

ChallengePush notification
Verified
Also supportedPasskeys (FIDO2) · TOTP · Duo MFA for Entra ID · SMS/Email OTP

Uses an existing Microsoft Authenticator or Duo enrollment

Okta Identity Cloud
Core verification

Okta Verify

ChallengeNumber challenge
Verified
Also supportedPasskeys (FIDO2 WebAuthn) · TOTP · SMS · Email OTP

Uses the employee’s current Okta enrollment

Entra Verified ID
Policy-driven step-up

Verified ID + Face Check

ProofCredential + face match
Assured
PurposeHigher-assurance verification

Applied when organizational policy requires it

Use Fctr Portal—or bring Fctr Verify into your existing tools.

Give helpdesk teams a faster path through security policy: run governed identity operations in one Portal, or trigger the same verification policy from the tools agents already use.

Fctr Portal

Identity operations workspace

Look up employees, verify callers, and take approved actions in one governed workspace.

Illustrative sandbox view · sensitive values masked

Best whenYou need one workspace instead of admin consoles and spreadsheet handoffs.

Fctr Verify

Verification where agents already work

Trigger verification from an active ticket, support session, or customer application.

Customer-deployed integrationsOne integration included
ServiceNow
Freshdesk
Zendesk
Slack
Microsoft Teams
APIExternal Verification API

Best whenYou need to keep agents in their current tools while enforcing verification.

Use Fctr Portal, Fctr Verify, or both. For supported workflows, agents use Fctr roles and policy instead of switching among provider consoles or holding broad direct administrative access.

Live identity context. PII-masked evidence.

Fctr retrieves only what an active support session needs. PII-masked evidence connects the actor, factor, policy, action, and outcome. Review the public assurance overview.

No shadow identity directoryCurrent context comes from the system of record.
Less direct provider privilegeFctr roles constrain supported actions without broad agent access to provider consoles.
Connected audit evidenceActor, factor, policy, action, and result remain connected for operational, compliance, and cyber-insurance evidence requests.
CONNECTED SUPPORT RECORD Why the action was allowed
EventActorControlOutcome
Identity context retrievedHelpdesk agentDirectory readCOMPLETE
Device proof acceptedEmployeeExisting MFAVERIFIED
Scoped action recordedHelpdesk agentPolicy + targetRECORDED
Illustrative product view · sensitive values masked by design

Pricing for the way your team works.

Simple, predictable pricing for Fctr Portal, Fctr Verify, or both.

02 / FCTR VERIFY Standalone for organizations with up to 5,000 workforce identities $35,000 / year ONE INTEGRATION INCLUDED
  • Sandbox environment for setup and integration testing
  • Enrolled-factor verification in an existing support workflow
  • Predictable annual pricing—not user-based or per-verification
  • +Additional integrations — $15,000/year each

Need pricing tailored to your organization? Talk to us.

Discuss Verify
ENTERPRISE 03 / ENTERPRISE For larger organizations and advanced requirements $50,000 / year STARTING PRICE

For Verify deployments above 5,000 workforce identities or more complex platform requirements.

  • Custom connectors and implementation support
  • Dedicated deployment options
  • Premium support and SLA options
  • Complex multi-environment planning
Contact sales
Helpdesk workflow impact From multiple consoles to one workspace.
~5 minMulti-console flow <60 secCaller verification
Discuss your workflow →

The answers buyers need before a pilot.

Straight answers to the questions security and identity teams ask before connecting a workflow.

We already use Okta or Microsoft Entra ID. Why do we need Fctr?

Entra ID and Okta secure application access. Fctr binds a caller’s enrolled-factor proof to sensitive helpdesk actions: Portal gates authorized actions, while Verify returns the result to customer-deployed workflows.

How do employees verify callers claiming to be IT support?

The IT caller starts a request in Fctr Portal under the organization's verification policy. The employee independently opens Fctr in Teams or Outlook, checks the pending request, and selects the phrase the caller says. The employee never reads the choices back to the caller. This confirmation does not authorize a password reset or other support action.

Will caller verification slow down helpdesk SLAs?

Fctr Portal replaces console switching and manual handoffs with one workspace, reducing caller verification from about five minutes to under 60 seconds. Fctr Verify keeps agents in their existing queue.

Which existing MFA methods can Fctr use?

Fctr supports configured passkeys, Microsoft Authenticator Push and TOTP, Duo MFA for Entra ID, Okta Verify and number challenge, and Entra Verified ID with Face Check for higher-assurance step-up. Available methods depend on provider configuration and tenant policy.

What data does Fctr access from our identity provider?

Fctr uses scoped API access to retrieve identity context for the active support session without building a persistent workforce directory. Personal and recovery contact details are excluded from approved audit records. Organization-issued email addresses and UPNs are masked in human-readable audit labels; limited identifiers remain for security correlation and auditability.

How is Fctr deployed and integrated?

Organizations can connect a pilot to Okta or Entra ID with scoped tokens or OAuth 2.0, then use the browser-based, cloud-hosted Fctr Portal or Fctr Verify through a customer-deployed integration or the External Verification API. A sandbox demonstration requires no tenant access, and a connected pilot can be deployed in days; full rollout timing depends on integration, policy, and change-management requirements.

How are Fctr Portal and Fctr Verify priced?

Fctr Portal starts at $250 per agent per month with a five-agent minimum. Fctr Portal customers add Fctr Verify integrations for $15,000 per year each. Teams without Portal can license Fctr Verify for $35,000 per year for organizations with up to 5,000 workforce identities, with one integration included. Enterprise pricing starts at $50,000 per year for organizations with more than 5,000 workforce identities or advanced deployment requirements. Additional integrations are $15,000 per year each. Fctr Verify uses predictable annual pricing rather than per-user or per-verification pricing.

How does Fctr help protect against AI voice cloning and deepfake callers?

Fctr helps protect against AI voice cloning and deepfake vishing by requiring verification through supported organization-managed factors, rather than trusting a familiar voice or face. Biometric-protected approvals can be used where enabled by the provider and organization. Fctr Portal keeps supported sensitive actions unavailable until verification succeeds and role and policy permit them. Fctr verifies callers; it does not analyze audio or video to detect deepfakes.

View all frequently asked questions

See it first. Then try it in your environment.

See Fctr in action.

We’ll show caller verification, policy, and supported actions working together in Fctr’s sandbox. Want hands-on access? Connect your Entra ID or Okta tenant and use Fctr for 60 days.

Request a demo.

Tailor the demo Optional

Used only for this request. Privacy policy.