- DATE:
- AUTHOR:
- The Transmit Security team
Mosaic’s New Releases Bring Smarter Detection and Greater Control
August and September brought new capabilities to detect sophisticated fraud, strengthen device management and create more flexible identity experiences across Mosaic. New behavioral signals help identify social engineering scams in real time, while expanded device controls provide greater visibility into how devices and authenticators are used and give teams more agency over their lifecycles.
Highlights
Detect Social Engineering Scams Through Behavioral Signals
Detection and Response can now identify behavioral signals indicating that a legitimate user may be acting under the influence of a third party—a common pattern in authorized push payment (APP) and other social engineering scams. New mobile signals, including active phone-call detection, audio routing, device orientation and phone-to-ear proximity, help identify behavior consistent with real-time coaching or coercion, providing additional context for detecting scams even when the genuine user is performing the transaction.
* General availability
Customer Identity Management
Unified Device and Authenticator Management
A new device management experience provides a unified way to understand and control the devices associated with users and the authenticators registered on or used from them. New journey steps and APIs enable teams to register, evaluate and manage devices, while administrators can view and suspend devices to block authentication and lock device-bound authenticators, such as PIN and mobile biometrics, until the device is reactivated.
Organizations can also set application-specific limits for registered web and mobile devices. When a limit is reached, Mosaic can automatically remove the least recently used device to make room for a new one or block additional registrations, depending on the configured policy. Separate limits and auto-deletion settings for web and mobile give teams greater control over device lifecycles according to each application’s security and access requirements.
* General availability
Independently Verify Transaction Approvals Offline
Transaction signing flows now provide the cryptographic artifacts needed to independently verify and store transaction approvals offline, helping organizations support audit and regulatory requirements. Available for mobile biometrics, passkeys, and PIN, the new signing artifacts include the approval and signed data, signature, public key, and authenticator information needed to validate each approval outside of Mosaic.
Signing artifacts are also available as output variables in Identity Orchestration, including for cross-device transaction signing flows, making it easier to incorporate verification and recordkeeping into existing journeys.
* General availability
Fraud Prevention
Support Data Privacy by Managing Fraud Prevention User Data Programmatically
A new Clear User API enables teams to programmatically delete a user’s stored data from Fraud Prevention, making it easier to support privacy requirements and automate data lifecycle management through backend workflows.
* General availability
Orchestration
Create More Flexible Journey Logic with Custom Branches
Custom Branches are now available across additional external connection types, extending conditional branching beyond Custom HTTP to Token Validation, Custom OIDC, and Custom Web Service SMS, Email, and Push connections. Teams can define conditions that route journeys through dedicated SuccessErrororWarning paths based on responses from external services, providing greater flexibility to handle different outcomes without custom logic.
* General availability