What passkey elevation is
Passkey elevation is step-up verification: your organisation chooses which sensitive actions require extra proof, and performing one of them asks you to verify with a passkey before it goes through.
What it protects
Admins switch passkey elevation on for categories of sensitive action, and any action inside a protected category then needs a passkey. The eight categories are:
Resource access configuration — creating and updating the access config for a resource.
Access catalog configuration — creating and updating access catalogs.
Direct access changes — granting someone access to a resource directly, and revoking access they already have.
Access approvals — approving or rejecting an access request as an admin, and approving, rejecting or rolling back a provisioning batch.
Offboarding — creating, starting or deleting an offboarding, and changing the offboarding configuration.
API key management — creating, updating or revoking API keys.
Team management — inviting someone to the dashboard, changing a team member's role, and removing a team member.
Security settings — SSO and SAML configuration, the dashboard and employee-portal IP allowlists, revoking a dashboard session, and revoking member portal tokens.
What it is not
Passkey elevation is not a sign-in method and not login multi-factor authentication. People sign in exactly as they do today, with SSO or a magic link. The passkey is only ever asked for at the point of a protected action, never when you log in.
How verification works
Each verification requires a biometric or a device PIN — possession of the device alone is not enough. One verification keeps your session elevated for a configurable window, and repeated protected actions inside that window do not re-prompt you. The window defaults to 15 minutes and can be set anywhere from 1 minute to 8 hours.
A passkey belongs to the person, not the organisation. If you work in several Ploy organisations, you register once and it works in all of them. Elevation itself is per organisation, though: verifying in one organisation does not carry into another, so switching organisations means verifying again there.
What it covers, and what it does not
Passkey elevation covers actions taken in the dashboard and actions taken through Luna. A protected action can never be performed autonomously by Luna — it is held for human confirmation, and the person confirming must have an elevated session. One verification covers confirming a batch of them.
Passkey elevation does not cover anything done with an API key or by an automated flow.
Next steps
Read the rest of this collection in order: