Identity · Cyber Security · Product Engineering

Verified Orchestration.

ID by VO gives enterprises verifiable identity at the moments that matter most: onboarding, helpdesk resets, account recovery, passkey enrolment. We built the first MVP with VO's team on site in Sydney, and came back to engineer the full orchestration platform now running in production with enterprise customers.

The product

Identity failures rarely happen during routine logins. They happen when trust is being created, restored or overridden: a new starter being issued credentials, a caller asking the helpdesk to reset an account, an urgent access request outside normal process. These are exactly the moments attackers target, because they are the moments organisations fall back on security questions and judgement calls.

Verified Orchestration replaces those judgement calls with cryptographic proof. Built on Microsoft Entra Verified ID, the platform issues verifiable credentials anchored to real identity verification, then lets any workflow, service desk tooling, IAM platform or customer system verify them instantly, with biometric matching including Face Check where impersonation risk demands it. It is a genuine crossover of the two things we care most about: cyber security thinking and production engineering.

First, the MVP

The engagement began where good product engagements begin: with a founding team, a thesis about verifiable credentials, and the need to prove it in working software. Our Sydney consultants worked on site with VO's team to build the initial MVP, close enough to the whiteboard to shape the product decisions, not just implement them.

The MVP did what an MVP should: it proved that Microsoft Entra Verified ID could carry the experience VO wanted to sell, and it did so quickly enough for the founders to put it in front of real prospects. That evidence is what turned a thesis into a product roadmap worth backing.

Then, the platform

When VO was ready to build the full orchestration platform, they came back, and the engagement grew from an MVP team into sustained product engineering. What exists today is a multi-tenant platform spanning the whole credential lifecycle: an orchestration API exposing both GraphQL and REST, an administration console for composing credential schemes, issuance flows and verification requests, a user-facing portal for credential holders, an OIDC service so verified identity can stand behind ordinary sign-in, and a client SDK for embedding verification into customer systems.

The engineering underneath is Azure end to end: TypeScript and Node services, Entra ID for authentication, infrastructure defined in Terraform, observability through Azure Monitor and OpenTelemetry, and a deliberate data posture in which personally identifiable information lives in claims and controlled storage rather than application databases. Issuance runs at batch scale, credentials can be suspended and revoked from one place, and every identity decision is logged for audit.

How the team runs

This is our embedded model at full stretch. Coder Trove engineers work on site in Sydney with VO's own people, inside their standups, sprints and codebase, owning work end to end from feature development through review, automated testing and release.

The delivery discipline is the part we would show any prospective client: test-driven development, end-to-end test suites in Playwright, automated dependency and vulnerability management on a standing cadence, and versioned releases that roll through non-production, sandbox and per-customer production instances in a controlled sequence. For an identity platform, that discipline is not engineering vanity. It is the product: nobody buys trust infrastructure from a team that ships casually.

Where it stands

The platform is live, running verifiable credential issuance and verification in production for enterprise customers in Australia and internationally, with releases shipping on a steady cadence and the engineering team still embedded years after the first line of MVP code. From a founding thesis to trust infrastructure other enterprises build on: that is the arc this engagement was hired to deliver, twice.

Microsoft Entra Verified ID Entra ID TypeScript Node.js GraphQL Azure Terraform Playwright

Building a product that has to be trusted?

Identity, security and payments products are only as good as the engineering discipline behind them. If you are building one, talk to the team that builds them for a living.