The person you interviewed is not always the person at the keyboard
Your company verifies a candidate at interview, a person at background check, and a document holder at right to work, then never asks again. Each check is sound. None of them connect. That gap has a name, and it is where laptop farms live.
The hire was excellent. Senior backend engineer, remote, strong system design interview, two references who returned calls quickly and spoke warmly. The final round ran ninety minutes on video with three people and nobody had a bad word.
Six weeks in, the engineering manager has a feeling she cannot make into a sentence. The camera is worse now than it was in the interview, which is odd, because most people upgrade after they get the job rather than downgrade. Standups are audio only about half the time, and the reason given is always plausible: bad hotel wifi, a broken laptop camera, a noisy room. The written English in pull request comments is noticeably better than the spoken English in meetings, though plenty of excellent engineers are stronger in writing. Commits land in a window that does not match the stated timezone, but remote work is remote work and people have children and gyms and lives.
Every single signal has an innocent explanation. That is not an accident of the story. It is the design of the attack. Nothing in that list is evidence, and an engineering manager who escalates on the basis of camera quality is going to have a difficult conversation with HR about what exactly she is alleging and on what grounds.
So she does what almost everyone does, which is nothing. And the honest reason she does nothing is not timidity. It is that there is no system anywhere in the company she can query to answer the only question that matters: is the person doing this work the person we interviewed? Recruiting has an answer about a candidate. Background check has an answer about a legal identity. IT has an answer about a device. Payroll has an answer about a bank account. Not one of them is connected to the others, and not one of them was designed to be asked again later.
Short answer. Hiring fraud is usually described as a verification problem, but companies verify a great deal. It is a continuity problem. Identity is checked at four or five separate seams by four or five separate systems, each using a different identifier, and nothing carries the verified human forward. Binding the candidate to a one-way person key at first contact and re-attesting that key at each later seam is what makes the question "is this the same human" answerable at all.
Why can't anyone say whether the person working is the person you hired?
Because the employment lifecycle is not one identity process. It is five or six unrelated ones that happen to concern the same body, run by different departments, using different identifiers, on different timelines, with different vendors, and with no shared key between them.
Walk it slowly, because the shape of the failure only becomes obvious when you see every seam laid out at once.
| Seam | Who owns it | What it actually verifies | The identifier it keys on |
|---|---|---|---|
| Application | Recruiting, ATS | Nothing. A form was submitted | Email address |
| Interview | Hiring team | A person appeared on video and answered questions | Calendar invite, a face nobody recorded |
| Offer and acceptance | Recruiting, HR | Someone with the email accepted terms | Email address, e-signature |
| Background check | Third party vendor | A legal identity has a record history | Name, date of birth, national ID |
| Right to work | HR | A document was presented and looked genuine | Document number |
| Device issue | IT | A laptop was shipped to an address | Asset tag, shipping address |
| First login | IdP, IT | Someone holds the credential that was sent | Username, enrolled authenticator |
| Payroll enrolment | Payroll | Someone submitted bank details | Employee number, account number |
| Ongoing work | Nobody | Nothing is verified again, ever | Session cookie |
| Offboarding | IT, HR | An account was disabled | Username |
Read down the identifier column. Email address, calendar invite, national ID, document number, asset tag, username, employee number, account number, session cookie. Nine identifiers, none of which is derived from any of the others, describing what is supposed to be one person.
Now consider what that means operationally. If you wanted to prove the person who joined the interview is the person who logged in on day one, there is no join key. You would be comparing a memory of a face against a username. If you wanted to prove the person working in month six is the person who logged in on day one, you would be comparing one session against another session, which proves only that both sessions had the credential.
Each individual check is fine. The background check firm does competent work. The right to work review follows the rules. The identity provider correctly validates an authenticator. The failure is not inside any of them. It is in the spaces between them, which belong to nobody.
Every seam is a swap opportunity
Once you see the seams, the attack patterns stop looking exotic and start looking obvious, because each one is just a substitution at a boundary that nothing spans.
A proxy interviewer sits the technical round and hands off after the offer. The identity that was assessed and the identity that arrives are different people, and no artifact from the interview persists to contradict it. A laptop farm operator accepts the shipped device in a permitted country and provides remote access to an operator elsewhere. The device posture is perfect, the location is correct, and the human is somebody else entirely. A contractor wins the engagement and quietly subcontracts the actual work to a cheaper colleague, sharing the login, which the contractor sees as efficient rather than fraudulent. A departed employee's tokens keep working because offboarding disabled an account without touching independently issued credentials.
Our laptop farm playbook walks the mechanics of the infrastructure side, and resume fraud in the AI era covers what has happened to the document layer. Both describe the same underlying gap from different angles.
What is identity discontinuity?
Here is the naming, because the thing needs a name before it can be fixed.
Identity discontinuity is the structural failure in which identity is verified at moments and assumed for durations. Every control in the employment lifecycle is a moment. Employment is a duration. Moments do not chain to each other on their own, and no vendor in the market is paid to make them chain, because each vendor is paid for its moment.
The analogy that makes it land is a passport at a border. A border officer checks your passport, matches your face to the photo, and stamps you in. That check is careful and real. What it establishes is that at 14:32 on Tuesday, a person matching that document crossed that line. It establishes nothing at all about who is in the country on Thursday. Countries handle this by accepting that residency is not continuously verified, and by putting controls at other boundaries instead.
Companies made the opposite bet without noticing. They verify hard at the boundary and then grant a durable, high privilege, remotely accessible position that is never re-checked, in a work model where the person is never physically seen. The border check was calibrated for a world where the employee then walked into an office every day and was, in the most literal sense, continuously verified by everyone who saw their face.
Remote work removed the ambient verification that everyone was relying on without ever having designed it. Nobody replaced it, because nobody had ever specified it as a control in the first place. You cannot budget to replace something that was never on the list.
What does discontinuity actually cost?
The clearest evidence is the North Korean remote worker programme, because it has been documented by governments rather than by vendors. Actions and advisories from the US Department of the Treasury and the Department of Justice describe a coordinated scheme in which operatives obtain remote technical roles at Western companies using stolen or fabricated identities, with laptop farms inside the United States receiving company hardware, generating revenue for the sanctioned state that these actions describe in the hundreds of millions of dollars annually. Reporting on DOJ enforcement through 2024 and 2025 describes farms serving well over one hundred US companies. Figures vary between sources and reporting periods, so treat the exact numbers as directional; the structure of the scheme is not in dispute and is documented in the primary actions themselves.
What makes it relevant here is not the espionage angle. It is that the scheme is a pure exploitation of the seams. The operatives pass background checks, because the legal identity they borrowed is real and clean. They pass right to work, because the documents belong to a real person. They pass device posture, because the laptop is genuinely the company laptop sitting in a permitted location. They pass identity provider checks forever, because they hold the credential. There is no seam where the deception is detectable by the control that sits at that seam.
On the front end, Gartner's widely cited projection that a substantial share of candidate profiles globally will be fake within a few years is quoted constantly in recruiting circles, and while the precise figure and date should be checked against Gartner's own publication before anyone puts it in a board deck, the direction matches what talent teams report. Our deepfake hiring playbook covers the interview stage specifically.
On the back end, vendor analyses through 2025 have reported that a large majority of machine credentials associated with former employees remain active after offboarding. Vendor figures deserve scepticism about methodology, but anyone who has run a real access review recognises the pattern.
Add it up for one incident. A senior salary paid for months, the cost of a forensic investigation, remediation of whatever was accessed, potential sanctions exposure if the counterparty was designated, notification obligations if data moved, and the organisational cost of every colleague who now wonders about everyone else. One sleeper on the payroll clears a million dollars without difficulty.
Why doesn't better verification fix it?
Because more of a thing that does not chain still does not chain. This is the part that most buying committees get wrong, and it is worth being specific about each option.
Identity verification vendors sell moments, well
Document plus selfie verification at onboarding is a real control and does real work. It establishes that at the moment of onboarding, someone holding this document had this face. It produces a pass or fail and, typically, no durable artifact that a later system can query. It was designed for account opening, where the moment genuinely is the risk, and it is very good at that. Asking it to secure a two year employment relationship is asking a border stamp to be a residency permit.
Background checks are about a record, not a body
A background check answers whether a legal identity has a history. It is excellent at that and it is why background check vendors are a mature industry. It cannot tell you whether the person who will do the work is the person whose record was pulled, because the check runs against a name and a national identifier, not against a key held by whoever shows up.
Periodic video re-verification is expensive and now weak
The natural answer is a video call every quarter with someone from HR. This is costly at scale, awkward for everyone involved, and increasingly ineffective. Injection attacks against verification pipelines, where synthetic video is fed directly into the capture layer rather than held in front of a camera, have been reported at large volumes by identity verification providers, and the cost of producing convincing synthetic video has collapsed. A control whose security rests on a human on a call deciding whether a face is real is a control being asked to win a race it has already lost. Our deepfake defence matrix compares the detection vendors honestly.
Behavioural monitoring watches the wrong thing
Keystroke dynamics, mouse patterns, and productivity analytics are sold as a continuous answer. Three objections. It profiles the behaviour of every honest employee to catch a rare dishonest one, which is a poor trade and increasingly a legal problem. It produces probabilities, and a probability is not something you can put in front of an employment tribunal. And a proxy worker who has been doing the job for six weeks looks exactly like the person who has been doing the job for six weeks, because they are the same set of behaviours performed by different hands.
There is also a design objection that matters more than the practical ones. Monitoring makes the employee the subject of investigation. Any control that requires treating your entire workforce as suspects to catch a handful of impostors will be resented, resisted, and eventually removed, and it deserves to be.
How does continuity work without a biometric database?
This is the mechanism, and the constraint that shapes it is simple: we want to answer "same human as before" without ever holding a biometric that could be stolen, subpoenaed, or sold.
The primitive is a one-way person key. At first contact, typically the first interview, the candidate's device performs a face match locally, in the browser, and derives a stable key from the result. The face never leaves the device. No template is uploaded. What is stored is a key that can be recomputed by the same person on a later occasion and cannot be reversed into a face. There is no vault of faces because there is no vault.
Paired with that is the enrolled device signature. The person registers a passkey, which is what makes later checks cheap: most seams need only a signature, and the face match is used at the small number of moments where a fresh liveness check is genuinely warranted.
Then, at each seam, the same key is asked for again, and each answer produces a receipt. That is the whole idea. Not a new check. The same check, threaded.
{
"thread": "manav:thread:8f21c0",
"seam": "first-login",
"personKey": "pk_9c41...e07a", // one-way, derived on device
"matchesThread": true, // same key as interview and offer
"assurance": "device-bound+liveness", // passkey signature plus fresh match
"priorSeams": ["interview", "offer", "right-to-work"],
"issuedAt": "2026-09-06T09:14:22Z",
"heldBy": "worker", // receipt lives in the worker's wallet
"sig": "ed25519:71ab...4f9c"
}
The receipt says: this seam was passed by the same person key that passed the earlier seams, at this assurance level, at this time. It verifies offline against a published key, so an auditor, a client, or a future employer can check it without calling us and without a database lookup.
Note what is not in that object. No image. No template. No location history. No behavioural score. No productivity data. The receipt is small and boring on purpose, and boring is the security property.
Which seams are worth attesting?
Not all of them, and picking too many is the most common way to make this unpleasant. A defensible set for a remote engineering role is: first interview (establish the thread), offer acceptance, first login on the issued device, first payroll cycle, any grant of privileged production access, and offboarding. Six moments across a multi-year relationship. That is not surveillance by any reasonable definition; it is roughly the frequency at which you already ask people to do compliance training.
Is this surveillance?
It is the first question any workforce audience asks, it is asked in good faith, and it deserves a serious answer rather than a reassuring one.
The short version: monitoring observes what you do, continuously, and produces a judgment about you. Continuity confirms who you are, occasionally, and produces a receipt you own. Those are different activities with different data, different frequency, different ownership, and different failure modes.
| Dimension | Employee monitoring | Identity continuity |
|---|---|---|
| What it collects | Keystrokes, screenshots, app usage, camera samples, activity timing | A one-way key and a signature at a handful of moments |
| Frequency | Continuous during working hours | Roughly six times across an employment relationship |
| Output | A behavioural score or productivity judgment | A yes or no on "same human", with a receipt |
| Who holds the record | The employer, indefinitely | The worker, in their own wallet |
| Portability | None. It dies with the job and cannot help you | The worker can present receipts to a future employer, with consent |
| What a breach exposes | A detailed record of how someone worked | Keys that cannot be reversed into a face |
| Effect on the honest employee | Permanent suspicion, measurable stress | Six taps, and a portable record of their own history |
The portability row is the one that converts this from a control imposed on workers into something a worker might actually want. A monitoring record is a liability that belongs to the employer and helps the employee never. A continuity thread is an asset that belongs to the worker: a verifiable history of having been the same person across roles, which is exactly the artifact a contractor or a remote worker in an unfamiliar market currently has no way to produce. Our writing on the verified work passport develops that side.
None of which means the concern disappears. Any identity control can be operated badly. The safeguards that matter are structural rather than promissory: no biometric template stored anywhere, receipts held by the worker rather than the employer, a fixed and disclosed list of attested seams, and no derived judgment about performance. If an implementation drifts from any of those, the objection becomes correct.
A maturity model you can locate yourself on
- Level 0, moment only. One identity check at hire. Nothing after. This is where most companies are, and it is not negligence, it is the default the industry shipped.
- Level 1, boundary discipline. Verification at hire plus a real offboarding process that revokes machine credentials, not just the account. Cheap, and it closes the most common orphaned-access failure.
- Level 2, thread started. A person key established at first interview and re-checked at first login. This alone closes the interview-to-day-one swap, which is the single highest value seam.
- Level 3, seams attested. The key re-attested at offer, first login, payroll, and privileged access grants, with receipts retained. Now you can answer the manager's unaskable question with an artifact.
- Level 4, portable and worker owned. Receipts live in the worker's wallet, travel to the next employer with consent, and reduce that employer's onboarding cost. This is where the network effect starts and where the worker gets paid back for participating.
Most organisations should target level 2 this year and level 3 next. Level 4 is a market outcome rather than a project.
Honest limits
- Coercion defeats it. A person who is genuinely present and genuinely signing, under duress or for payment, produces a valid receipt. Continuity proves sameness, not willingness. Some of the DPRK cases involve a witting facilitator, and no signature scheme addresses that.
- Consensual credential sharing is hard to distinguish from fraud. A contractor who shares work with a colleague can also share the moment of the check. Attesting at unpredictable seams raises the cost, but this is mitigation, not prevention.
- First enrolment is the trust bottleneck. If the very first face match is performed by an impostor, the thread is perfectly consistent and perfectly wrong. Continuity proves sameness from enrolment forward, which is why binding at the earliest possible seam matters.
- Jurisdictional variation is real work. Biometric processing sits under Article 9 of the GDPR as a special category, and state laws such as the Illinois Biometric Information Privacy Act impose notice and consent duties. On-device matching with no stored template is a much better position than a template vault, but "better" is not "exempt", and counsel should be involved before rollout.
- It does not judge work. Continuity says the same human is present. It says nothing about whether that human is doing the job well, and it should not be repurposed to try.
- Cross-employer portability needs adoption. A worker-held receipt is only valuable if the next employer accepts it. Today that means a small number of participating organisations, and honesty requires saying so.
What to do this week
- Draw your own seam table. List every identity check from application to offboarding, who owns it, and which identifier it keys on. The gaps become obvious on one page and the exercise takes an afternoon.
- Find your join key, or confirm you have none. Ask whether any single value connects the interview to the first login. Most companies discover the answer is an email address, which the candidate controls.
- Run the six week test on a recent remote hire. Not to accuse anyone. To find out what evidence you could produce if you had to, and how long it would take.
- Fix offboarding first. It is the cheapest level up. Enumerate machine credentials and API keys tied to departed staff in the last six months, not just their accounts.
- Pick your two highest value seams. For most organisations they are interview-to-first-login and privileged production access. Start there rather than attempting the full lifecycle.
- Write the worker-facing explanation before you write the policy. If you cannot explain in one paragraph what is collected, what is not, who holds it, and why it helps the worker, the rollout will fail regardless of the technology.
- Try the flow. The interview continuity demo shows a thread across interview rounds, the employee verification demo shows the day-one seam, and the developer docs cover the API.
The thread is the product
Go back to the engineering manager with the feeling she cannot make into a sentence. The tragedy of her position is not that the company failed to verify anyone. The company verified a great deal. It ran a background check, reviewed documents, shipped a device to a confirmed address, and enrolled a strong authenticator. Every one of those checks passed, and every one of them was answering a question about a different identifier at a different moment.
She does not need another check. She needs the checks that already happened to be connected, so that "is this the same person" is a lookup rather than an accusation. That is the entire idea. One key, established as early as possible, asked again at a handful of meaningful moments, producing receipts the worker owns and can carry forward.
Verification is a moment. Employment is a duration. Until something spans the gap, the seams will keep being where the money goes.
Frequently asked questions
How do you know the person working is the person you hired? Today, in most companies, you do not, because no identifier connects the interview to the first login to month six. Continuity works by establishing a one-way person key at first contact and asking for that same key again at later seams, producing a receipt each time. The question becomes a lookup instead of a suspicion.
What is identity continuity in hiring? Identity continuity is proof that the human at a later moment is the same human verified at an earlier one. It differs from identity verification, which establishes who someone is at a single moment. Employment is a duration, so continuity is the property that actually matters after day one.
Is continuous employee identity verification the same as employee monitoring? No. Monitoring observes behaviour continuously and produces a judgment about a worker, held by the employer. Continuity confirms identity at roughly six moments across an employment relationship, collects no keystrokes, screenshots or productivity data, and produces receipts the worker holds and can carry to a future employer.
How do companies detect laptop farm and proxy workers? Detection is difficult because every individual control passes: the borrowed legal identity clears a background check, the shipped device shows correct posture and location, and the credential holder authenticates correctly. The gap is that no control asks whether the working human matches the interviewed human, which is a continuity question rather than a detection question.
Does this require storing employee biometrics? No. The face match runs on the worker's own device and derives a one-way key. No image or template is uploaded or stored, so there is no biometric vault to breach or subpoena. This matters legally as well as practically, given GDPR Article 9 and state biometric privacy statutes.
Should employees be re-verified after hiring? At a small number of meaningful seams, yes. A defensible set is offer acceptance, first login, first payroll cycle, any grant of privileged production access, and offboarding. That is roughly six checks across years, which is comparable to the frequency of existing compliance obligations and is not surveillance.
What happens at offboarding? Closing the thread produces a signed end-of-thread record that revokes downstream authority derived from it. This matters because disabling an account does not disable independently issued machine credentials, and vendor analyses have repeatedly reported that most former-employee machine credentials stay active after departure.
Sources
- US Department of the Treasury press releases, including actions and advisories on the DPRK remote IT worker programme. https://home.treasury.gov/news/press-releases
- US Department of Justice, Office of Public Affairs, enforcement actions on laptop farms and remote IT worker schemes. https://www.justice.gov/opa/pr
- USCIS I-9 Central, including the alternative procedure for remote document examination. https://www.uscis.gov/i-9-central
- NIST Special Publication 800-63A, Enrollment and Identity Proofing. https://pages.nist.gov/800-63-3/sp800-63a.html
- GDPR Article 9, processing of special categories of personal data. https://gdpr-info.eu/art-9-gdpr/
- Gartner newsroom, for the original wording and date of the fake candidate profile projection. https://www.gartner.com/en/newsroom
Verification is a moment. Employment is a duration. The seams between them belong to nobody, which is exactly why that is where the money goes.