Security Guide · For Organisations
You don't need to understand the cryptography. This is the short version: what you, as the person running the organisation, need to understand and do so your customers or staff can sign in with a fingerprint, face, or PIN instead of a password.
A passkey replaces the password with the fingerprint, face, or PIN.
They unlock with a fingerprint, face, or PIN. No password to type, reset, or forget.
There's no shared password sitting on your servers to be grabbed — or tricked out of your customer by a fake site.
They tap a sensor they already own — and they're in.
Try it on the devices your people actually use. You're checking one thing: can a normal person sign in, first time, without calling for help?
| Device | What the user does |
|---|---|
| Windows laptop | Using Windows Hello, Looks at the camera, uses the fingerprint reader, or types a PIN |
| Mac | Touches the Touch ID button |
| iPhone / iPad | Face ID or a fingerprint |
| Android phone | Fingerprint or screen unlock |
| Security key | Plugs in the key and touches it (e.g. a YubiKey) |
Passkeys take work away rather than adding it. Here's what stops being your problem.
For accounts that use a passkey, there's no password database to protect, reset, or lose sleep over.
No authenticator app to set up, and no six-digit codes to copy across from your phone. The check happens on the device.
Nearly everyone already has a phone or laptop that can do this. Only sensitive roles might need a security key.
For most businesses this is a feature your existing login system or vendor can switch on — not a rebuild.