---
source_url: "https://product.transmitsecurity.com/announcements/new-directions-in-identity-b2b-orchestration-geolocation-insights-and-more"
title: "Mosaic Platform Release Notes | New Directions in Identity: B2B"
mirrored_at: 2026-08-13T01:05:40.119Z
host: product.transmitsecurity.com
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/product.transmitsecurity.com/announcements/new-directions-in-identity-b2b-orchestration-geolocation-insights-and-more"
---

> **Original source:** https://product.transmitsecurity.com/announcements/new-directions-in-identity-b2b-orchestration-geolocation-insights-and-more

This edition marks a major leap in how Mosaic supports real-world identity at scale. With the introduction of _B2B Identity Orchestration_, customers can now design complete journeys for business users, bringing enterprise-ready flexibility to the core of our platform. Paired with powerful _geolocation features_ like mobile signals and a global risk map, this release deepens both visibility and control across fraud detection and identity flows. Together, these and other updates expand what’s possible with Mosaic and give you the tools to build more intelligent, context-aware and secure experiences across all user types.

> ## Highlights

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f3e2.png) Orchestrate End-to-End B2B Identity Journeys

Mosaic now supports [**B2B Identity Orchestration**](https://developer.transmitsecurity.com/guides/orchestration/getting-started/b2b_tutorial/), giving customers with B2B CIAM use cases the ability to design and manage full identity journeys for business users. This includes flows for inviting, authenticating and managing members across partner organizations, subsidiaries and enterprise customer accounts.

With Orchestration, teams can build tailored B2B journeys that meet specific business requirements, including:

-   Custom onboarding flows for invited members
    
-   Flexible login experiences for enterprise users
    
-   Org-level access policy enforcement
    
-   Scalable management of identities across companies
    

Journeys are built through the same drag-and-drop interface used for consumer flows, ensuring a consistent orchestration experience across all identity types.

\* _Available in sandbox_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f4f8.png) **Auto Capture Now Available in Web and iOS SDKs**

The Web SDK and iOS Mobile SDK for [**identity verification**](https://developer.transmitsecurity.com/guides/verify/identity_verification_experience/#) now support an auto-capture experience. This feature automatically detects and captures document and selfie images when framing, lighting and clarity meet optimal conditions. By reducing the need for manual taps, it improves image quality, increases verification accuracy and creates a smoother user experience, increasing conversion—even in challenging environments.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdSOqYE02-P2PazPtBOjlglfdQ_cvyC4PMvfwwComrLHuGg18Pv8lW2tQGMCSobO1XsKVzmwzGhp1_KJDMhoCx8gW0uoIRa-jedz4Ln5zptlqLEGUYg9gNKLljj_25MtWHkzogyvg?key=mcpbO7MYghBxSC0X7qHkhQ)

_\* Available in sandbox_

> ## Identity Verification

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f465.png) Detect Reused or Synthetic Profiles With Multi-Session Matching

A new Repeated Profile [**security insight**](https://developer.transmitsecurity.com/guides/user/security-insights/) helps detect synthetic or stolen identities during identity verification by analyzing patterns across multiple sessions. The system checks for similarities in key profile attributes such as full name and date of birth and identifies discrepancies in extracted data that may indicate manipulation or reuse.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeZ4s_AqZLHM9EWCW8YqxWiZ7EcuDHo-tyrEkr9obmoqYi9mPwgR3cxDUaL3eJmnykdRkL4vCawLZN4KzKQTCFTPVnS5b_ve28Nz3YFD_paSc4TEJ37gHr7yrcYKnAKBDRm8Cbt?key=mcpbO7MYghBxSC0X7qHkhQ)

\* _Available in sandbox_

> ## Fraud Prevention

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f5fa-fe0f.png) Visualize Geolocation Risks With the New Fraud Prevention World Map

A new map visualization on the Fraud Prevention overview page highlights geolocation risks to help fraud teams spot where malicious or suspicious activity is most prevalent. Users can drill into specific regions for deeper analysis and trend exploration. The map is powered by IP-based geolocation, offering approximate regional context without exposing exact physical locations.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXct8UVzd5CPnCAHGOmRNurD8tD_78uWNYcyAMQ44yw4UdFZuBFmPVVT51emuA_7hcgC1YKvouGvM14muGE6g3O8PgCtDdFO_RM1zbTfS-5e0Dpse3s9NCmg5frPOtmvI7lnNp17?key=mcpbO7MYghBxSC0X7qHkhQ)

\* _General availability_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f4cd.png) Enhance Detection With Mobile Geolocation Signals

Our Fraud Prevention services now support mobile geolocation signals for more precise fraud detection. By collecting data from GPS, Wi-Fi and cellular sources, the system builds accurate geolocation profiles and identifies deviations that may signal risk. Detection scenarios include new location, impossible travel, trusted location, mismatches and spoofing.

The collection endpoint is configurable based on use case, desired accuracy and data freshness. This feature helps reduce friction by assessing location context automatically, offering high accuracy with minimal user effort. Availability for iOS is coming soon.

\* _Early availability (Android)_

> ## Customer Identity Management

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f522.png) Authenticate With PIN Code for Device-Based Login

A new PIN code authentication method is available, providing a simple and secure way for users to log in from trusted devices. This option improves flexibility while maintaining strong security, especially in mobile-first experiences where ease of use is key.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXf3eMux2tXhB5N0cIk1dNbLzB0S7lS7Kuyr2zPPi7M15F20Bolq5nk6VfZjGfVxG-uhAosF61TEBBKNpIV1NjX1Ppgkpg-BQKoOqRUcsFk5eU9yL1aQiaG45YqnAg8TMPvYQYFjyg?key=mcpbO7MYghBxSC0X7qHkhQ)

PIN Code authentication can be fully customized and integrated into your orchestration flows:

-   [**Customize authentication methods**](https://developer.transmitsecurity.com/guides/user/auth_methods_customize/#pin-codes)
    
-   [**Register a mobile PIN**](https://developer.transmitsecurity.com/guides/orchestration/journeys/register_mobile_pin/)
    
-   [**_Authenticate using a mobile PIN_**](https://developer.transmitsecurity.com/guides/orchestration/journeys/authenticate_mobile_pin/)
    

\* _General availability_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/267f.png) WCAG 2.1 Accessibility Support for Hosted Experience and B2B Org Admin Portal

Both the Hosted Experience and the B2B Org Admin Portal now support WCAG 2.1 accessibility standards, improving usability for people with disabilities and aligning with modern accessibility best practices. With this update, we ensure that Mosaic experiences are more inclusive, compliant and user-friendly across the board.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXc35U2LjyBc9mNoiRnMRrQAr8lKtsxMaIx9sfYktDdPOdi1x470iHXmotgW_JhG3ZxhiUQ1Y2_RdDqc0GQOcYCle-SCzBvuGTNLfKwGGp7hWFm9USIi6BbIjwpeN2hVvcODZ7WChg?key=mcpbO7MYghBxSC0X7qHkhQ)

\* _General availability_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f510.png) Stronger Security for PKI-Based mTLS Authentication

Two important enhancements have been added to improve control and trust in [**PKI certificate-based mutual TLS**](https://developer.transmitsecurity.com/guides/user/auth_fapi_mtls/), strengthening authentication and policy enforcement for mTLS flows:

-   _Certificate Chain Validation_ confirms that the client certificate is part of a trusted chain.
    
-   _Subject DN Validation_ allows inspection of specific fields in the certificate’s Subject DN, such as Common Name (CN) or Organization (O).
    

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfrDrY1ZbLH7CPyHipN_MXWz1dgJQ4kI-aCSI5nag7qQY3zadvTgUfi1zfwl07_ExZp04tofGjV2GZekxT2qrPkHscs_vBoqbfRRWbbYJZEzQgpg4WoVEdSmeICFA7KA9MC5O_Onw?key=mcpbO7MYghBxSC0X7qHkhQ)

\* _General availability_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f36a.png) New SameSite Cookie Setting for OIDC and SAML Clients

A new SameSite configuration is available under Advanced Settings for both OIDC and SAML clients. By default, the setting is LAX, with None available as an additional option.

When set to None, cookies are marked as Secure and all redirect URIs must use HTTPS. Validation is in place to prevent insecure configurations. This update is essential for supporting cross-site login flows and embedded use cases—such as authentication within iframes or across domains—while preserving strong security standards.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcZPdTv4gi5H6rzuXTWgDrDoCNDsjQVyYuV12f75s8Y21Oo3URfXH2gcamjK8rt-CES-OhhSwdtYmzcF5_443S2MDLg__QSz8KWmgDWHrQgifDl4vHPqRRj6bO_2AcnVDOzi5hnyQ?key=mcpbO7MYghBxSC0X7qHkhQ)

\* _General availability_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f512.png) Stop Brute-Force Attempts with Lockout Controls for Passkey Authentication

Passkey authentication now includes configurable lockout settings to protect accounts from brute-force attempts or repeated misuse, strengthening account security while maintaining a seamless user experience.

\* _General availability_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f5dd-fe0f.png) Access WebAuthn Public Keys via the User Authenticators API

WebAuthn public keys and related metadata are now available through the [**User Authenticators API**](https://developer.transmitsecurity.com/openapi/user/authenticators/#operation/userAuthenticators), giving customers direct access to essential credential data. This improves authentication resiliency by enabling fallback handling in the event of a SaaS outage.

\* _General availability_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/2699-fe0f.png) Control Which Client Is Used for B2B Invitation Flows

A new setting lets you explicitly select the OIDC client used for B2B member invitations. This prevents failures caused by clients that require PKCE, which is not compatible with magic link flows. The setting appears just below the “Application URI for inviting members” field and ensures that only non-PKCE clients can be selected.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdkTv2Rs84ZSmI5dgi4vbh26aZ5hJNPcV6BoINnO7AslT0rfY8PNSvUR3pJWPCsfh806cPE7rmAcJh17Mli5jsvIEKKAvR5OlOqWOxd64sguHBG2PgTt73fgjbWy6L_f6_7UuuSSA?key=mcpbO7MYghBxSC0X7qHkhQ)

\* _General availability_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f4c4.png) Enhanced B2B Logging for Admin Actions

B2B logging has been improved to offer greater visibility into administrative activity across the _Org Admin_ and _Tenant Admin_ portals:

-   _Tenant Admin_ actions on members are logged as _Admin Activity_, capturing both the acting admin and the affected member.
    
-   _Org Admin_ actions on members or organizations are logged as _User Activity_, clearly identifying the actor and the target entity.
    

These updates strengthen auditing, support security investigations and improve transparency across B2B operations.

_\* General availability_

> ## Orchestration

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f6ab.png) Customize the User Experience After SSO Access Rejection

SSO journeys now support a configurable Access Rejected setting, giving you control over what users see when access is denied. You can display a custom rejection message with personalized title, message and button text, or redirect users to a specified destination with an error string passed in the URL.

\* _General availability_

### ![](https://cdn.jsdelivr.net/npm/emoji-datasource-apple/img/apple/64/1f504.png) Pass Contextual Metadata From Web to Mobile Journeys

An “Additional Data” section has been added to relevant journey steps, making it easier to carry context across channels and improve decisioning on mobile. This allows you to pass metadata such as IP address or browser type from web to mobile journeys through a dedicated data object.

\* _General availability_