Identity Proofing and Verification of an Individual: Full Process
Here's something that will make you rethink how age verification actually works: when a well-designed interoperable digital ID system is running, the staff checking your age never see your face matched against a photo. No side-by-side comparison. No AI scoring your facial geometry against a driving licence image. They receive a binary signal, yes or nobacked by a cryptographic proof that was locked in when the credential was first issued. The facial comparison already happened. Upstream. Once. And it's sealed.
The real shift in age verification isn't accuracy, it's interoperability: one biometric credential, issued once, cryptographically verified across any platform without repeating the facial comparison every time.
That's not a future scenario. It's what Yoti and Luciditi demonstrated at the 2026 Global Age Assurance Standards Summit, and it signals something much larger than a single product demo. It signals where the entire identity verification industry is heading, and it fundamentally changes the question professionals in this field need to be asking.
Biometric Identity Verification: Bouncer to Credential Shift
Think about how age verification has worked for decades. A bouncer at the door checks your ID. They look at your photo, look at your face, and make a call. Every venue, every night, every patron, the matching happens fresh each time, performed by a human eye (or increasingly, a point-of-sale camera system) at the exact moment of access. That model made sense when identity credentials were physical objects that anyone could theoretically forge.
Starts at 01:57 — this story3:17
Watch this story, in under a minute
A new briefing every weekday — three stories, three minutes.
Subscribe on YouTubeNow think about how a passport works in a visa-on-arrival system. One trusted government authority verified your identity, issued a cryptographically secure document, and now dozens of countries can authenticate that document without re-running the original identity check. They trust the issuer's signature. The verification happened once, at issuance, and that single event anchors every subsequent interaction.
That's the architecture Yoti and Luciditi built for age verification, and the implications go well beyond pubs and online age gates. Digital certificates presenting an age claim are signed by a certification authority and presented as QR codes through a proof-of-age app, allowing authenticity to be confirmed both online and offline. The trust isn't vendor-specific. It's standard-based, designed to work across independent providers, including Yoti ID, Post Office EasyID, and Luciditi, all recognising each other's credentials without requiring the end user to re-enrol. This article is part of a series, start with India Biometric App Cancellation Trust Adoption Backlash.
That cross-recognition is the whole point. That's interoperability.
Zero-Knowledge Proofs: Cryptographic Technique Behind Identity
Here's where the technology gets genuinely interesting. The privacy mechanism underpinning these interoperable credentials is called a zero-knowledge proof, or ZKP, and it's one of those concepts that sounds abstract until you understand what it actually does, at which point it becomes kind of beautiful.
A zero-knowledge proof allows one party to prove to another that a statement is true without revealing why it's true or any information beyond the truth of the statement itself. In age verification terms: a person can cryptographically prove they are over 18 without sharing their date of birth, their name, their address, or any document. As Google's blog on ZKP technology explains it, "a person can verifiably prove they are over 18 without sharing anything else at all." Nothing. Just the confirmation.
The technical machinery behind this involves something called a zkSNARK, a zero-knowledge Succinct Non-interactive ARgument of Knowledge. Without diving into the full arithmetic, the system uses circuits to verify that a hidden input (your actual birth date) satisfies a condition (older than the threshold) and produces a proof that any verifier can check without ever seeing the input. Critically, the EU Age Verification Blueprint's technical specification includes unlinkability guarantees, meaning verifiers cannot associate multiple proofs with the same user, even if they try. Every verification event looks cryptographically fresh.
What does this mean for the facial comparison workflow? The biometric matching, your face against your identity document, happens exactly once, at credential issuance. After that, the system doesn't need your face again. The verification point receives a proof, checks the cryptographic signature of the issuing authority, and returns a binary answer. The bouncer's eyes are no longer in the loop. Previously in this series: China Ai Avatar Deepfake Consent Rules Compliance.
"With businesses only receiving a simple confirmation of age, staff are no longer required to visually match a customer's face to an ID image." Biometric Update, reporting on the Luciditi-Yoti interoperability agreement
The Misconception That Keeps Tripping People Up
Most professionals working in identity verification assume the opposite of what's actually happening. The assumption goes something like this: AI facial recognition is getting more accurate every year, so naturally, digital identity systems will use more facial comparison, at more touchpoints, with higher precision. Better AI, more matching. Seems logical.
It's wrong. And honestly, it's easy to see why people get there. The accuracy narrative is real, modern facial recognition systems have improved dramatically, and that improvement is well-documented and widely covered. But accuracy improvements at the matching stage led engineers to ask a more interesting question: if we can match faces reliably once at enrolment, why are we doing it again at every verification point? That's like re-fingerprinting someone every time they swipe a building pass.
Interoperable identity architecture with ZKPs answers that question by moving the facial comparison upstream and eliminating it everywhere else. The biometric work is done at credential issuance. Everything downstream is cryptographic trust, not repeated comparison. The identity professionals who understand this distinction, who know the difference between verification at issuance versus verification at access, will have a significant edge as these systems become standard.
At CaraComp, we work with facial comparison technology daily, and this distinction matters enormously for how the field develops. The question for practitioners isn't "how accurate is the matching?" anymore. It's "where in the identity workflow does the matching happen, and who controls the trust signal that results?"
Why Scale Changes the Conversation
Here's what stops the skeptic in their tracks: this isn't theoretical. The Luciditi-Yoti interoperability agreement already covers a network of 7 million users across the UK. That's not a pilot. That's not a proof-of-concept gathering dust in a conference room. That's operational scale. Up next: India Tried 6 Times To Force A Biometric App On Your Phone A.
And the market intelligence behind it is striking. Reusable digital identity verification, the category these systems sit in, represents a forecast global opportunity of $11.4 billion by 2030, according to UK-based analyst Goode Intelligence, as reported by Biometric Update's coverage of the 2026 GAASS demonstration. What's interesting about that number isn't its size, it's what it reveals about where institutional capital thinks the value lies. The money isn't chasing systems that lock users into a single vendor's verification loop. It's chasing systems that reduce re-verification friction across any platform. Interoperability isn't just an architectural preference. It's where the investment thesis points.
There's a technical term for what makes this work at scale: reusability versus interoperability. They're related but distinct. Reusability means you can use the same credential multiple times with the same provider, verify once, reuse the result. Interoperability means you can use that credential across different providers, across systems that were built independently. The Yoti-Luciditi demonstration achieves both simultaneously, which is the harder problem. Getting two competing identity platforms to mutually recognise each other's credentials, certified under the UK's Digital Identity and Attributes Trust Framework, is the kind of thing that sounds obvious in hindsight and takes years of standards work to actually accomplish.
What You Just Learned
- 🧠 Biometric matching happens once, at issuancein interoperable ZKP systems, the facial comparison is done when the credential is created, not repeated at every verification point
- 🔬 Zero-knowledge proofs transmit confirmation, not dataverifiers receive a cryptographic yes/no answer without ever seeing the underlying identity document or biometric
- 📊 The market is already voting with capital$11.4B forecast for reusable identity by 2030 signals that interoperability, not accuracy alone, is the competitive differentiator
- 🔑 Reusability ≠ interoperabilityusing one credential multiple times with one provider is reusability; using it across independently built systems is the harder, more valuable problem
The future of biometric identity verification isn't about better facial matching at every door, it's about matching once, issuing a cryptographically sealed credential, and building networks where that credential is trusted everywhere. The battleground has shifted from accuracy to interoperability, and the professionals who understand that shift will be the ones who know where facial comparison still matters and where it's being deliberately designed out.
So here's the question worth sitting with, and it applies whether you work in identity verification, investigations, platform compliance, or biometric system design. If a person's age credential has already been verified by a certified authority, sealed with a zero-knowledge proof, and confirmed by a 7-million-user network, what's the remaining job of facial recognition at the point of access? The answer isn't nothing. Liveness detection, fraud prevention, and credential binding still need it. But the "did this face match this document" question? That's already been answered. Permanently. Upstream. And the entire identity industry is now building systems that treat that answer as a trust signal, not a starting point.
That's a fundamentally different world than the one where a bouncer squints at your driving licence in dim light and makes a judgment call. Whether that world is better or just different, well, that depends entirely on who controls the certification authority at the top of the chain.
Identity Authentication Versus One-Time Matching
Identity authentication is the ongoing question, is this the same person who was verified before?, while the original biometric match answered a different, one-time question: does this face belong to this document? Interoperable systems separate the two deliberately. Authentication after issuance relies on the cryptographic proof, not a fresh biometric comparison, which is exactly why the verification point never needs a camera at all.
Identity Proofing at the Point of Issuance
Identity proofing is the upfront work of confirming that a person is who they claim to be before any credential gets created. This is where the biometric data, the document check, and the human identity actually converge, once, carefully, under conditions the issuing authority controls. Everything the rest of the system does afterward, including every downstream authentication, borrows its trust from how rigorous that proofing step was.
Biometric Data and What Verifiers Never See
Biometric data in this model stays locked inside the issuance event. The verifier never receives the facial image, the fingerprint template, or any raw biometric data, only the cryptographic proof that says the match succeeded. That's a meaningful privacy upgrade over systems where biometric data gets transmitted, stored, or compared at every single checkpoint.
Facial Recognition's Narrower, More Precise Job
Facial recognition still matters, but its job has narrowed. Instead of running at every access point, facial recognition now typically does one thing well: confirming, at enrolment, that the live person matches the photo on the identity document. Once that facial recognition event is sealed into a credential, subsequent systems lean on the proof instead of repeating the comparison.
Fingerprint Recognition in Layered Verification
Fingerprint recognition follows a similar logic in systems that use it. It's typically deployed as a secondary or layered check, useful for liveness detection and fraud prevention, rather than as the sole basis for every transaction. Where fingerprint recognition is used, the underlying template is usually protected the same way facial biometric data is: sealed at capture, not re-transmitted at every check.
DHS Standards and Cross-Border Trust
Agencies like DHS have long pushed for standardized, interoperable identity credentials in travel and border contexts, and the logic mirrors what Yoti and Luciditi built for age verification. A DHS-recognized document works because the issuing check was trusted once, not because every checkpoint re-runs the original biometric proofing from scratch.
Biometric identity verification, taken as a whole, is shifting from a repeated-comparison model to a proof-once, trust-everywhere model. Identity authentication, identity proofing, biometric data protections, facial recognition, and fingerprint recognition are no longer separate silos, they're stages in a single pipeline, each doing a distinct job so the others don't have to repeat it. That division of labor, more than any single accuracy improvement, is what's actually reshaping the industry.
For practitioners building or auditing these systems, the practical consequence is a shift in what "secure" even means. Security no longer depends on catching a bad facial match at every door; it depends on how well identity proofing was done at issuance, how tightly biometric data is sealed afterward, and how much of the fraud detection burden gets pushed onto liveness detection and behavioral signals instead of repeated identification checks. Verification, in other words, is becoming an architecture decision as much as a biometric one, and that's the detection layer worth watching next.
In-Person Proofing Versus Remote Identity Verification
In-person proofing is the original identity verification model: a person shows up, a document is checked by human eyes, and a face is compared to a photo on the spot. In-person proofing still has a role in high-assurance cases, but it doesn't scale the way remote identity verification does, and it doesn't produce a reusable proofing process on its own. Interoperable credential systems borrow the rigor of in-person proofing and compress it into a single issuance event, so the identity verification of an individual only has to happen carefully once rather than repeatedly at every counter.
Identity Evidence and the Proofing Process
Identity evidence is whatever a proofing process actually examines, a passport, a driving licence, a utility bill, a biometric sample, to establish that a claimed identity belongs to a real, unique individual. A sound proofing process weighs multiple pieces of identity evidence together rather than trusting a single document, because any one piece of identity evidence can be forged while a combination is far harder to fake convincingly. The strength of identity proofing for an individual depends directly on how much identity evidence was checked and how carefully the proofing process cross-referenced it.
Identity Verification Standards and the Identity Document
Identity verification of an individual usually starts with an identity document: a passport, a national ID card, or a driving licence that carries a photo and biographic details. The identity document gets checked for tampering, checked against known security features, and checked against watchlists before it's trusted as identity evidence for the rest of the proofing process. When identity verification relies on a single identity document without a second, independent identity evidence source, the resulting proofing process is only ever as strong as that one document's authenticity checks.
Identity Proofing Is a Process, Not a Single Check
Identity proofing is not one check, it's a process built from several smaller checks stacked together: document authentication, biometric matching, database cross-referencing, and sometimes a live interview. Identity proofing is essential precisely because a person's claimed identity has to survive more than one kind of scrutiny before an issuing authority extends real trust to it. Treating identity proofing as a single pass-fail moment misses the point; it's a layered process, and the identity proofing process is only as strong as its weakest layer.
Biometric Identity Verification as a Confirming Process
Biometric identity verification is best understood as confirming that someone is who they claim to be by checking a live trait against a trusted record, not as a single photo comparison repeated at every door. In practice, biometric identity verification means the heavy lifting, the actual biometric identity verification event, happens once, at issuance, and every later checkpoint simply trusts the result. That framing matters because it changes what a security team should be auditing: not the camera at the door, but the proofing event that happened upstream.
Person's Identity Using Unique Physical Traits
At its core, biometric verification confirms a person's identity using unique physical traits, a face, a fingerprint, an iris pattern, that are difficult to fake and don't change from year to year. Systems built this way use unique physical traits precisely because they're harder to steal than a password, and a person's identity using unique physical characteristics can be checked without ever exposing the raw biometric data itself. That's the design goal: confirm identity, reveal nothing extra.
Specific Biographic Information Stays Separate
A well-built system keeps specific biographic information, birth date, address, document number, separate from the biometric proof that gets shared with a verifier. The zero-knowledge approach means specific biographic information never has to leave the issuing authority's records at all; only a yes-or-no answer travels downstream. That separation is what makes the whole model more private than older approaches, where a full document image (and everything printed on it) got handed over just to confirm one fact.
Biometric Recognition Across the Verification Chain
Biometric recognition sits at the front of this chain, doing the one job nothing else can do: tying a physical human being to a specific identity record. Once that biometric recognition event is complete and sealed, authentication, fraud detection, and identification checks downstream can all lean on it instead of repeating it. Security teams auditing these systems should treat biometric recognition as a single point of truth, not a repeated ritual performed at every door.
Authentication, Fraud Detection, and Secure Identification Working Together
Authentication, fraud detection, and identification now function as a coordinated set of checks rather than three separate hurdles a user has to clear. Secure authentication confirms the credential is genuine, fraud detection watches for patterns that suggest the credential is being misused, and identification ties the whole transaction back to a real person without re-running the original biometric match. Building secure systems this way means each layer catches a different failure mode, so a weakness in one doesn't automatically break the others, a meaningfully more secure design than relying on one identification step to catch everything.
Digital Identity Proofing and Customer Onboarding
Digital identity proofing is what happens before a customer ever gets an account: a provider needs to verify identity, check an identity document, and confirm the person applying is a real, unique individual before granting access. Customer onboarding built around digital identity proofing typically asks a new user to submit an identity document, take a selfie for selfie verification, and wait while the system cross-checks both. Done well, digital identity verification lets a business verify identities instantly instead of routing every new signup through manual review, which is exactly why digital identity proofing is essential to onboarding at scale. The person is confirmed once, at the start, and every account action after that leans on that first digital identity check.
Verifying customer identities remotely is harder than it sounds, because a provider has to confirm user identities remotely without ever meeting the applicant in person. That's why digital identity verification usually combines a document scan with a live selfie: the system checks that the identity document is genuine, then checks that the face in the selfie matches the photo on that document. When both checks pass, the provider can say with confidence that the person is who they claim, and can easily prove they are that person again later using the same digital identity record instead of repeating the whole process.
Fraud is the reason so much of digital identity proofing exists in the first place. Account takeover, synthetic identity fraud, and stolen document fraud all rely on a weak identity check somewhere in the onboarding flow, so providers add layers of identity verification specifically to close those gaps. Risk teams look at signals like document tampering, mismatched selfie verification, and reused identity documents across many accounts, then score each application for risk before an account is approved. A strong digital identity proofing setup can quickly flag the accounts that deserve a closer look while letting everyone else through without friction.
Identity verification for customer onboarding is not just about catching fraud, though, it's also about proving that identity proofing is essential to keeping honest customers safe. If someone else tries to open an account using a stolen identity document, a good digital identity verification system will catch the mismatch before an account is created, protecting both the real person and the business from downstream fraud and risk. That's the practical value of digital identity proofing: it verifies a person's identity once, quickly, so both the customer and the provider can trust every account interaction that follows.
Biometric identity verification depends on more than just capturing a face or fingerprint once, it depends on how well that biometric data is protected afterward. When a system stores biometric data as an encrypted template rather than a raw image, even a database breach doesn't hand an attacker anything usable for identification. That's why serious identity authentication programs treat biometric data protection as part of the security architecture, not an afterthought bolted onto the biometric identity verification step.
Secure authentication and secure storage go hand in hand in any system built around biometric identity verification. A provider that promises secure onboarding but stores biometric data in plaintext has not actually built a secure system, no matter how good its detection algorithms are. That's why auditors checking authentication flows now ask specifically how biometric data is encrypted, where it's stored, and who can access it, not just how accurate the initial identification was.
Fraud detection has gotten more sophisticated precisely because identification alone is no longer enough to stop synthetic identity fraud. Modern fraud detection layers behavioral signals, device fingerprinting, and document authentication on top of the original biometric identity verification event, so a stolen credential still triggers a detection alert even if the underlying identification data looks clean. Detection, in this sense, is a continuous process that runs long after the initial authentication succeeded.
Identification and authentication are often used interchangeably, but they answer different questions inside a secure system. Identification asks who someone is; authentication asks whether this specific claim of identity is genuine right now. A secure digital identity proofing system needs strong identification at the start and continuous authentication afterward, because fraud detection works best when both layers are feeding it signals rather than just one.
Biometric data collected during identity proofing has to be handled differently depending on jurisdiction, which is part of why secure design matters so much in this space. Some regions treat biometric data as sensitive personal information requiring explicit consent, while others fold it into broader identification rules; either way, a provider building secure authentication has to design for the strictest standard it operates under. Getting that wrong doesn't just risk a compliance fine, it undermines the trust the entire identification chain is built on.
Security teams evaluating a digital identity proofing vendor should ask pointed questions about biometric data handling before signing anything. Where is biometric data stored, how long is it retained, and does authentication rely on a raw biometric or an irreversible template? A vendor that can't answer clearly on identification, fraud detection, and biometric data retention isn't offering a secure product, no matter how polished the onboarding flow for the end user looks.
Proofing Identity Before Any Credential Exists
Proofing identity is the step that happens before trust can exist anywhere downstream. A provider proofing identity has to confirm the document is genuine, confirm the person holding it is the person pictured, and confirm that same person isn't already registered under a different name. Get proofing identity wrong at this stage and every later verification, however good the technology, inherits that same weakness.
Digital environments make identity proofing both easier and harder at once. Easier, because a document can be scanned and checked against known templates in seconds instead of minutes. Harder, because digital environments also give fraudsters more ways to submit a manipulated image or a synthetic identity document without ever standing in front of a person. That tension is exactly why verification process design matters as much as the underlying algorithm.
MFA plays a supporting role once digital identity proofing is complete, not a replacement for it. MFA confirms that the person logging in still controls the phone, email, or authenticator app tied to the account, which is a different question than whether that account was set up by a real, verified person in the first place. Pairing strong identity document checks at onboarding with MFA at every login is how a provider keeps the verification process a person's identity was built to be.
ID verification vendors are increasingly judged on how quickly they can complete a document verification without pushing more risk downstream. A verification process that takes an applicant thirty seconds to complete but silently allows a forged identity document is not actually a good verification process, it's just a fast one. Providers that get this right combine automated document verification with human review for edge cases, so speed and accuracy move together instead of trading off against each other.
Data points collected during onboarding, device signals, location, prior account history, feed into the same risk score that document verification and selfie verification produce. Assurance goes up when several independent data points agree, and drops sharply when they conflict, which is exactly the pattern fraud teams train their systems to catch. A single weak data point rarely sinks an application on its own, but a cluster of them pointing the same direction usually does.
Compliance obligations shape almost every choice a provider makes about digital identity proofing, from how long an identity document image can be retained to which biometric checks require separate consent. Meeting compliance requirements isn't just a legal checkbox, it's often the reason a verification process is designed to touch as little raw personal data as possible. Providers that treat compliance as a design constraint from day one usually end up with simpler, more auditable systems than those that bolt compliance on after launch.
Assurance in identity verification isn't a single number; it's a level that reflects how much confidence a provider has that the claimed identity matches the real person. Low assurance might be fine for a free trial account, but a financial transaction usually demands a higher assurance level backed by stronger document verification and biometric checks. Understanding what assurance level a given use case actually requires, rather than defaulting to the strictest possible check every time, is what lets providers keep the verification process fast for low-risk cases while reserving deeper scrutiny for the ones that carry real risk.
They claim their onboarding is instant, but instant and thorough are not the same promise, and providers that quietly skip steps to hit a speed target usually pay for it later in fraud losses. When a vendor says they claim near-perfect accuracy on document verification, it's worth asking what error rate they're actually measuring against and under what conditions. The providers worth trusting are the ones willing to show their verification process, not just the headline number.
Identity proofing and verification of an individual is ultimately a chain of trust, and each link has to hold on its own. The claimed identity a person presents at onboarding is only as good as the identity evidence backing it, the identity document authenticating it, and the proofing process cross-checking it against fraud signals. When an organization talks about identity proofing and verification of an individual as a single event, it usually means the front-loaded moment where an identity document, a selfie, and a database check all agree, but the guidance most standards bodies publish treats that moment as the start of a relationship, not the end of one.
Claimed identity only becomes a trusted identity once enough independent identity evidence lines up behind it, and that's exactly what a competent proofing process is designed to test. A person presenting a single identity document with no biometric verification backing it is offering a much weaker claimed identity than someone whose identity document, selfie, and biometric verification all agree. That's why guidance on identity proofing and verification of an individual almost always recommends combining an identity document check with some form of biometric verification rather than relying on either one alone.
Biometric verification plays a specific role inside identity proofing and verification of an individual: it ties the identity document to the actual person presenting it, closing the gap that document checks alone can't close. Without biometric verification, an identity document could be genuine but simply stolen, presented by someone who isn't the person pictured on it. With biometric verification added to the proofing process, that gap narrows sharply, because the live person now has to match the photo on the identity document as well as the biographic details it carries.
Guidance from standards bodies on identity proofing and verification of an individual generally separates the work into stages: collecting identity evidence, validating that evidence, and then verifying that the individual presenting it is the same individual the evidence describes. Each stage in that guidance exists to catch a different kind of fraud, a forged identity document at the validation stage, a stolen but genuine identity document at the verification stage, and a synthetic claimed identity at the evidence-collection stage. Following that guidance in order, rather than skipping straight to a single check, is what makes identity proofing and verification of an individual resistant to more than one type of attack at once.
The proofing process also has to account for individual differences in how identity evidence is available in the first place. Not every individual holds a passport, and not every claimed identity can be backed by the same set of documents, so a proofing process built around a single identity document type ends up excluding legitimate individuals along with blocking fraud. Good guidance on identity proofing and verification of an individual accepts multiple valid combinations of identity evidence, provided the combination still
Frequently asked questions
What is biometric identity verification?
Biometric identity verification is the process of confirming who someone is by matching a physical trait, such as a face, against an identity credential. Traditionally this comparison happened at the point of access, like a bouncer checking a photo against a face. Newer systems shift this matching upstream, performing the facial comparison once when a credential is issued rather than repeating it at every checkpoint.
How does interoperable biometric identity verification work for age checks?
Interoperable biometric identity verification works by issuing one biometric credential after a single facial comparison, then sealing that result with a cryptographic proof. When someone needs age verification later, staff receive only a binary yes or no signal backed by that proof. There is no side-by-side photo comparison repeated at each venue or platform, since the matching already happened once, upstream.
Why is interoperability considered the real shift in biometric identity verification?
Interoperability matters because it removes the need to repeat facial comparison every time someone proves their age or identity. Instead of accuracy being the main issue, one biometric credential, issued once, gets cryptographically verified across any platform. This was demonstrated by Yoti and Luciditi at the 2026 Global Age Assurance Standards Summit, signaling a broader industry direction.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
ID Scan Data Breach: 170 Million Faces Can't Be Reset
A reported id scan data breach exposed 170 million ID scans. Here's what's actually inside one of those scans, and why replacing your card doesn't undo the damage.
facial-recognitionBiometric Entry: One Setting Flags 42% of Real Fans
A stadium gate that reads your face in under a second isn't proof of a perfect system — it's proof someone chose which kind of mistake to allow. Here's how that choice actually works.
biometricsBiometric Building Access Control: 3 Checks, Not 1
A face match at your building's front door proves who you are — but not that you're allowed in. Here's the three-step check most people never think about, and why NYC lawmakers and building owners are fighting over exactly that gap.
