Trust Center → How verification works

How verification works

Four ways in, one question being asked, and two things that will never happen to your face.

Verification is a ladder, not a yes/no. Your badge shows how you were verified, so nobody has to pretend we checked something we did not. "License-verified RN" and "peer-vouched EVS" are both full members.

TierHowWho it coversWhere it sits
Invite A verified member vouches for you Everyone, including every unlicensed role Primary at launch. Invites are capped, and the person who invited you is accountable for the vouching — not for everything you later write.
Registry Match against NPPES, a state licensing board or a state nurse aide registry Licensed staff — roughly 50–60% of a hospital Primary for licensed members. Nothing from the registry record is kept beyond the match result.
Work email A domain we recognize as a healthcare employer Most staff at systems that issue email Secondary only. It ties your account to infrastructure your employer monitors — we say so before you use it, and we store a salted hash of the domain, never your address.
Badge photo Read once, in memory, and discarded Everyone with a badge The essential fallback, because it is the only credential the whole building has. Your device crops the face and barcode regions off before anything is uploaded.

Nothing on this page is running yet. Status Post has not opened, nobody has been verified, and the pipeline below describes how verification is being built rather than how it currently works. It is published now so the design can be checked and argued with while it is still cheap to change — which is the point of the externally-auditable principle, not a substitute for it.

What the badge actually says

Two facts, and never a third. How you were verified, and what you do. Never that Status Post vouches for your work, your judgement or your safety — we checked that you work in a hospital, and that is the whole of it.

What it says also depends on where you are standing. On your page, in Off Duty or on a listing, you are already writing as yourself, so the badge carries your actual title. On a story in Recovery, Huddle or Consult it carries the coarse class only. The reason is arithmetic: the name on a story changes with every conversation, but a role does not, and "Med-Surg Nurse, nights, 4West" is a small enough group to guess at. Some titles are a group of one — there is usually a single nurse manager on a unit — so those never appear on a pseudonymous story at all, whoever is asking.

That last rule cuts both ways, deliberately. It protects a manager who had the same shift everyone else did and wants to say so. It also protects the people in a room the guidelines promise can be used to criticise how a place is run — a visible manager in that room decides who speaks, and nobody has to be doing anything wrong for that to be true.

The two red lines

Never: face matching. We do not compare a badge photo to a selfie, and we never extract face geometry from any image. Deleting such a scan a millisecond later would not make it lawful, and the security benefit is smaller than it looks: face matching would tell us a badge belongs to the person holding it, which is a verification question, not an abuse one. Abuse is answered by capped invites limiting who gets in, by rooms that open only to a small verified group, and by members reporting content that humans then remove.

Never: government ID. No driver's licence, no passport, no third-party identity check that demands one. We do not need your legal identity, so we do not collect it and cannot lose it.

What the badge photo path actually does

  1. Your device crops the photo and barcode regions out before upload. What leaves your phone is the printed text.
  2. The remaining image is read — by software, or by a person under contract — to confirm it is a healthcare employer badge.
  3. The system emits four things: a yes/no, a coarse role class, a code for which method was used, and a timestamp.
  4. The image is discarded. Not stored, not hashed, not queued, not logged. A hash would still be a linkable identifier, so we do not keep one of those either.

The 18+ floor

Status Post is for adults. Hospitals employ people under 18 — student volunteers, some dietary and transport roles — and we are asking them to wait. The reason is that the honest posting this network is built for does not have a safe version for minors, and the alternative to an age floor is an age-estimation system that would need exactly the face processing we refuse to build.

If something here changes

Any change to this page that widens what we collect will be announced before it takes effect, with the date it changes. Narrowing it, we will just do.