Rock U - Security - Phone Number Lookup
Transcribed Video Content
Sometimes the best way to verify you is with the phone that's already in your hand. So using a text message that is sent and a six digit code you receive, you can skip the login process. And you can make it easier for attendees to do things check-in to your system. Now, if you're using the phone number lookup block, this is actually what it's gonna look for a visitor. So I have this set up for my site so that when someone logs in, they can use phone number lookup to verify themselves.
Let's look at how to set this up in Rock. So now we're on the home page and all you need to do is go to admin tools, settings, then we're gonna look for pages, go to the external home page, down to support pages, and scroll a little bit, then click phone number lookup. Now this phone number lookup page comes out of the box, and it has a really simple URL. And again, this is just another way to verify yourself in Rock. It's kind of a form of logging in.
And I've made this the default just for now so that I can show you what it looks to log in with this block. Now, when we come over here, we can see the actual block that we're using, the phone number lookup block, and I'm going to click on the block properties. And let's talk about how to set this up, but something I wanna mention right before that is it's very important. You can't use this unless you have an SMS number set up. And we have documentation and videos that tell you how to do that in But I've got an SMS number set up and that's necessary so that we can send the verification code that comes when you type in your phone number in Rock.
Okay. So we're looking at the block properties. One of the most important settings is authentication level. And I have it set to trusted login, but out of the box, it'll probably be on identified and this is the difference. So trusted login means when you log in using the phone number lookup block, whoever logs in can basically access anything on their account.
So we're trusting that this person has really verified themselves and that they should have access to everything on their account. But if you want just a quick way for someone to log in to either the mobile check-in block, for example, or to go to the attendant self entry page, then by picking identified, whoever logs in will only have access to that, to those pages, unless they go log in further. So the lookup block will be a way for them to verify themselves, but they can only do a couple things that aren't really dangerous. And if they want to do more on the profile, they'd have to log in further. And really whichever thing you pick here has to do with your organization, your value you set on security, and which you think would you rather trade off the user experience or would you rather make sure that everyone who has access is truly, truly verified?
Now moving on with the settings here, there's quite a few instructions we can set. And these are the actual instructions that pop up as you go through this verification process. So you can really tailor it to your organization. You can even add Lava and HTML to make it dynamic, make this content dynamic or make it look a very specific way. You can also pick what the text message that's sent to the person who's verifying their number actually looks .
Then you'll also pick the SMS number you want to use where the verification will be sent from. Then some important things, you can pick how many minutes someone has before their basically session where they're trying to verify their phone number with a code is reset. Then validation code attempts. How many times can someone try to validate themselves with their six digit code and fail before it's just considered a permanent failure. Or the IP throttle limit, that means for one IP address, Basically, how many times can someone submit phone numbers for verification in the same day even if it's successful?
And that just helps you because, , you can only send a limited number of messages. It costs money. So you wanna be able to limit this and also protect yourself from bots. But that's the actual setup for the block. Now let's look at what the actual process is for a user.
So now again, here's what the block looks , and here's a phone number for Ted Decker, and I'm gonna click lookup. We'll simply wait a second and I'm getting the code right now. I've entered it. Let's move on. And this is a situation you might come up against if multiple people have the same phone number listed on their profile, then once you log in and verify, you'll have to pick which individual you are.
Now, if there was only one person that had this phone number associated, which is generally the case, then you'd immediately move on to the next step. But I'm gonna say that I'm Ted Decker. And there you go, it's really that simple to use this. And this is such a great way to verify yourself for mobile check-in or in this case, we're on the attendance self entry screen and whoever's here can just easily take action, verify that they are who they say they are and do something a check-in. It's true, the six digit code is all that it takes.
Using this, you can do things passwordless login and self check-in, making verifying who you are that much easier.