Configuring flows in DaVinci
After you configure PingOne, perform additional configuration in PingOne DaVinci to enable all features and make the flows available to end users.
Steps
-
Import the solution into your initial environment:
-
In your production DaVinci environment, click Flows.
-
Click Add Flow > Import from JSON.
-
Select the JSON file containing the flows.
-
Click Import.
-
-
Configure DaVinci applications that invoke the Frontline Worker - Registration, Authentication and Account Recovery with ID Verification and Recognize - Main Flow and Frontline Worker - Remote User Registration.
Learn more in Creating an application and Configuring a flow policy in the DaVinci documentation.
-
On the Applications tab, click Add Application.
-
In the Name field, enter a name for the application.
-
Click Create.
-
On the Applications tab, find the application that you created and click Edit.
-
On the Flow Policy tab, click Add Flow Policy.
-
In the Name field, enter a name for the flow policy.
-
Select PingOne Flow Policy if you plan to invoke the flow using a PingOne redirect.
-
In the Flows section, select the Frontline Worker - Registration, Authentication and Account Recovery with ID Verification and Recognize - Main Flow.
-
In the Version section, select one or more versions of the flow to use.
-
Click Create Flow Policy.
-
In the Distribution field, set the weight for the selected flow to
100. -
Click Save Flow Policy.
-
Click Apply.
-
Repeat steps a - m for the Frontline Worker - Remote User Registration.
-
-
Enter or verify the values for each company variable that’s used in the Verified Frontline Workers flow pack solution.
These variables determine whether some processes and subflows are included or excluded.
-
Click the Variables tab.
-
Locate a variable and click the Pencil icon.
-
In the Value field, verify that the value is correct or enter a new value for the variable.
-
Click Update.
-
Repeat steps b - d for each remaining variable.
Company variables
Variable Description frontline_companyNameThe name of your company as it should be displayed in user-facing text.
frontline_remoteRegistrationRetryLimitThe maximum number of times a user can retry remote registration if retries are enabled.
frontline_isRetryRemoteRegistrationEnabledA Boolean that indicates whether a user can retry remote registration.
frontline_superviserAuthnRetryLimitThe maximum number of times a user can attempt to authenticate as a supervisor.
frontline_workerAuthnRetryLimitThe maximum number of times a user can attempt to authenticate as a worker.
frontline_threatDetectionRequiredA Boolean that indicates whether threat detection through PingOne Protect is required.
frontline_supportEmailAn email address user should use for support. This can be included in email templates.
frontline_envDomainThe PingOne regional domain for this environment. This is userd to construct the correct PingOne endpoints. Valid values for each region are:
-
North America (excluding Canada) (NA): pingone.com
-
Canada (CA): pingone.ca
-
European Union (EU): pingone.eu
-
Australia (AU): pingone.com.au
-
Singapore (SG): pingone.sg
-
Asia-Pacific (AP): pingone.asia
frontline_helpdeskEmailThe destination email for support requests.
-
-
-
Verify the configuration of the following connectors in your environment:
Connector Description Connector documentation PingOne
Enables DaVinci to view and update PingOne user information.
PingOne Notifications
Enables DaVinci flows to send users general communications using SMS, email, and voice message with PingOne’s notifications feature.
OIDC and OAuth IdP
Enables users to authenticate with an Identity Provider (IdP).
-
On the Connectors tab, find the connector that you want to verify and go to … > Edit.
-
Verify that the Environment ID, Client ID, and Region field values match your PingOne values.
-
(Optional) Copy the Client Secret from your PingOne environment to the Client Secret field.
-
For the PingOne Authorize connector, verify that the Endpoint matches the one found in PingOne in the Authorization > Decision Endpoints section.
-
If you made changes to the values, click Apply.
-
Repeat the previous steps for each remaining connector.
-
-
Configure the Frontline Worker - Registration, Authentication and Account Recovery with ID Verification and Recognize - Main Flow:
-
Click Flows.
-
Select the Frontline Worker - Registration, Authentication and Account Recovery with ID Verification and Recognize - Main Flow and go to … > Edit.
-
Click the Initialize Or Set Flow Variables node and set values for the following variables:
Variables
Variable Description protectRiskEvalIdThe ID of the PingOne risk policy you created in the previous procedure.
p1OnSiteRegistrationVerifyPolicyIdThe ID of the PingOne Verify policy you created for the Frontline Worker - Registration, Authentication and Account Recovery with ID Verification and Recognize - Main Flow in the previous procedure.
supervisorsPopulationIdThe supervisors population ID.
workersPopulationIdThe workers' population ID.
workerAppClientIdThe client ID for the worker app.
workerAppClientSecretThe client secret for the worker app.
onboardingWorkersPopulationIdThe currently onboarding workers' population ID.
remoteInviteNotificationTemplateNameThe name of the notification template to use for remote invites.
remoteInviteFlowLinkThe flow policy link for the Frontline Worker - Remote User Registration to use for remote invites.
inviteLinkTTL (in seconds)The amount of time for which an invite should be active before it times out.
p1AgreementIdThe ID of the agreement to use if your environment requires user agreement.
helpdeskRequestNotificationTemplateNameThe name of the notification template to use for help desk requests.
-
Click Save.
-
-
Configure the Frontline Worker - Remote User Registration:
-
Click Flows.
-
Select the Frontline Worker - Remote User Registration and go to … > Edit.
-
Click the Initialize Or Set Flow Variables node and set values for the following variables:
Variables
Variable Description welcomeNotificationTemplateNameThe name to display for the welcome notification.
p1VerifyPolicyIdThe ID of the PingOne Verify policy you created for the Frontline Worker - Remote User Registration in the previous procedure.
workersPopulationIdThe workers' population ID.
p1AgreementIdThe ID of the agreement to use if your environment requires user agreement.
-
Click Save.
-
-
Verify that the PingOne flow setting is correct for your environment.
Choose from:
-
If you want to launch the Verified Frontline Workers flow pack solution using a redirect, the flow must be configured as a PingOne flow.
-
If you want to launch the Verified Frontline Workers flow pack solution using the widget, the flow must not be configured as a PingOne flow.
-
Click Flows.
-
Click the Frontline Worker - Registration, Authentication and Account Recovery with ID Verification and Recognize - Main Flow.
-
Go to > Flow Settings.
-
If you plan to launch the flow through a redirect, click the PingOne Flow toggle.
-
If you made changes to the flow settings, click Save, close the flow settings pane, and click Deploy.
-
-
-
If you’re using a test environment, move the flows to your production environment:
-
In your testing environment, click Flows.
-
Click the Frontline Worker - Registration, Authentication and Account Recovery with ID Verification and Recognize - Main Flow flow.
-
Go to > Download Flow JSON.
Result:
The Export Flow panel opens.
-
Click Yes.
Result:
The flow and its subflows are downloaded locally.
-
Sign on to your production environment and click Flows.
-
Click Add Flow > Import from JSON.
-
Select the JSON file containing the flows.
-
Click Import.
-
Repeat steps a-h for the Frontline Worker - Remote User Registration.
-
Repeat the previous steps in your production environment.
-
-
Invoke the flow or flows using the widget or a redirect.
Choose from:
-
If you want to launch the flow in a separate window using a PingOne redirect, use the procedure in Launching a PingOne flow with a redirect in the DaVinci documentation. The Frontline Worker - Registration, Authentication and Account Recovery with ID Verification and Recognize - Main Flow flow can be launched with a redirect.
-
If you want to launch the flow in a widget within the user’s current window, use the procedure in Launching a flow with the widget in the DaVinci documentation. The Frontline Worker - Registration, Authentication and Account Recovery with ID Verification and Recognize - Main Flow can be launched with the widget.
-