# Production Approval Process

To ensure that your integration adheres to FCRA regulations and best practices, Checkr requires our partners to comply with a quick integration review. We will ask you to answer a few security questions and demonstrate your integration to one of our Partner Managers. You will be able to use your application in staging before receiving a production account. Live/production activity requires approval.

Download the [Partner Certification Requirements PDF](/assets/partnercertificationrequirementsv1-8.6dc207537d5a8fff2b316e6981098aa175d8509975c8722a36ac5eeca5a4edcf.9c1bb791.pdf) for a quick checklist of implementation components and functionality required for production approval. To assist in meeting certification requirements, Checkr also provides a [Postman collection](/assets/stagingenvironmentpostmancollection.965cad08a23e965cc912e2ff387d2098328d8627596ce407b2bcd958cefce26c.9c1bb791.json) that partners can use during development. Download the Postman collection [guide here](/assets/stagingenvironmentpostmancollection.4574049c64c126f4b0126b03d13adfc096f5c6174dd0a0e9a3df984386d44a5b.9c1bb791.pdf).

1. Use the [standard integration acceptance criteria](#standard-integration-workflow) as a guide to prepare for the demo. Make sure you can demonstrate the full checklist prior to scheduling your demo session.
2. Email us at [partners@checkr.com](mailto:partners@checkr.com) to schedule an integration review once your development is complete and ready for production use.
3. We’ll ask you to demonstrate your completed integration through screenshare (using a Google Hangout) by walking us through Checkr account creation and connection, Package selection, background check ordering, and review of results. We will also review your Checkr integration as a whole to ensure proper functionality and to answer any questions that you may have. A review typically takes less than 30 minutes.


That's it! We’ll approve your integration (or make suggestions) when the review is complete.

## Standard integration workflow

![Integration acceptance criteria](/assets/integrationacceptancecriteria.0c91f9288fcf79d0e7b59351e3e72416e4bbaac62a8e04dbc7f96f9bd0d57f9d.9c1bb791.png)

This is the checklist you will be evaluated against to be approved for production use.

**Acceptance criteria for standard integrations**

Security and Compliance requirements
After an app has been developed, but before it may be deployed to product, Checkr requires both a security and a compliance review for certification:

**Security Review:** Demonstrate the security of your application, specifically in regard to ensuring that candidate PII is handled properly, and that the risk of a data breach is minimized.

- **Integrity**: Do you store sensitive candidate PII (such as SSN or driver license) in your application? If so, which fields?
- **Confidentiality**: Do your logs contain sensitive candidate PII or client credentials? Attach an example log for the following two API calls:
  - POST https://api.checkr.com/oauth/tokens
  - POST https://api.checkr.com/v1/candidates
- **Authentication**:
  - Describe how a user authenticates to access your application. If you do not establish user identity, describe what actions are available to anonymous users.
  - Describe the methods used to encrypt internal storage of secrets (keys, tokens).


**Compliance Review:** Most integrations require recertification at regular intervals, or after updates to the partner application. Work with your Checkr Partner Manager to determine when recertification will be required for your application.

Connect to Checkr
Partner can demonstrate proper usage of the "Connect to Checkr" flow, both for new customers and existing customers.

- Partner uses the Checkr-Hosted Signup flow to facilitate the creation of a Checkr account.
- Partner displays connected state within application.
- The "Connect to Checkr" option lives in two intuitive places in the application, such as a Settings page, candidate workflow, or Marketplace listing.


Select Packages
Partner can demonstrate the user experience of selecting a Package from within the partner’s application.

- Package list is retrieved from the customer account.
- Customer has the ability to view the Package price and screening set.


Support Account Hierarchy
Partner can demonstrate the user experience of working with Account Hierarchy options.

- Work Location is sent with the Invitation call.
- Nodes are retrieved from the customer account (if they exist).
- Node-specific Package list is retrieved from the customer account.
- If no Packages are associated with the selected node, all Packages are listed for the account in the selection pulldown menu.


Request Background Checks — /invitations (Checkr-Hosted Apply Flow)
Partner can demonstrate proper use of a Candidate and Invitation resource.

- If available, partner pre-fills invitation with candidate data.
- Partner can demonstrate the creation of two reports using the same Candidate resource.
- Partner can send candidate’s work location to Checkr.


Display Results
Partner can demonstrate the user experience of viewing background check results from within the partner’s application.

- Customer can follow a link to the report in the Checkr dashboard.
- Customer can view the report status.


Adjudicate
Partner can demonstrate the user experience of navigating to Checkr to adjudicate a report.

- Customer can view adjudication decisions reflected in partner’s application (optional).