What is PEP?
Politically Exposed Persons (PEP) are individuals who hold prominent public positions or have close associations with such persons. Their accounts require enhanced due diligence and access controls.OTP Verification
6-digit code sent to staff phone
Audit Trail
Every access logged with IP & timestamp
Time-Limited
Access expires after session ends
Endpoints
Request Access
POST /api/v1/pep/request-accessGenerate OTP and send to authorized staffVerify Access
POST /api/v1/pep/verify-accessVerify OTP and grant temporary accessAccess Flow
1
Initiate Request
Staff member with
pep_access_authorized: true requests access to a PEP subscriber2
OTP Generated
System generates 6-digit OTP and sends via SMS to staff’s registered phone
3
OTP Expires
OTP is valid for 5 minutes only
4
Verification
Staff enters OTP to verify identity
5
Access Granted
Temporary access granted with full audit logging
Security Features
Role-Based Access
Role-Based Access
Only users with
pep_access_authorized: true in their profile can even request access to PEP accounts. This is set by system administrators.IP & Device Logging
IP & Device Logging
Every access attempt logs:
- Client IP address
- User agent string
- Request timestamp
- Staff user ID
- Subscriber ID accessed
Session Expiry
Session Expiry
PEP access is granted per-session only. When the staff member logs out or their session expires, new OTP verification is required.
Rate Limiting
Rate Limiting
Failed OTP attempts are tracked. After 3 failed attempts, the staff member is temporarily locked out.
Request Example
- Request Access
- Verify Access