Insights / Marketplaces & Consumer Products · · 11 min read
Verification in talent marketplaces: identity, portfolio and consent
A talent marketplace is only as trustworthy as its verification. How CastLyra approaches verifying creative talent and the brands that hire them: identity, portfolio ownership, image consent, business legitimacy, contact-detail rules and the trust signals that make each check visible and useful.
In most marketplaces, a bad transaction costs money. In a talent marketplace, it can cost much more. A model invited to a fake casting, a creator whose images are reused without permission, a photographer who delivers work and is never paid, a brand that hires someone presenting another person's portfolio. These are not edge cases. They are the reasons many creative professionals are wary of online platforms in the first place.
Verification in talent marketplaces is how a platform earns the right to connect strangers. CastLyra is Oryvelon's global marketplace for verified creative talent (models, creators and creative professionals) and the brands that work with them. Verification is not a feature bolted onto it. It is the product's core promise. This article explains how we approach it, and what we think any talent or services marketplace should consider.
Why talent marketplaces need more than a badge
Many platforms offer a single "verified" badge. It is easy to build and easy to understand. It is also easy to misread. Verified what, exactly? That an email address works? That a phone number received a code? That someone looked at a passport? That the portfolio belongs to the person?
A single badge compresses different claims into one symbol and invites users to assume the strongest one. That is a trust problem waiting to happen. If a brand believes "verified" means "this person's portfolio has been checked" when it only means "this person confirmed an email", the badge has made the platform less safe, not more.
Our approach is to break verification into distinct checks, run each one properly, and show each one honestly.
The checks, separated
For talent on CastLyra, the checks fall into four groups.
| Check | Question it answers | Typical evidence |
|---|---|---|
| Contact verification | Can we reach this person reliably? | Confirmed email and phone |
| Identity verification | Is this a real person, and who they say they are? | Government ID compared against a live capture, reviewed |
| Portfolio ownership | Is the work shown genuinely theirs or their own likeness? | Consistency checks, source files, credits, references |
| Consent and rights | Do they have permission to show this work here? | Declarations, photographer or client permissions where needed |
For businesses, the checks are different but just as important:
| Check | Question it answers | Typical evidence |
|---|---|---|
| Account verification | Is there a real, reachable person behind the account? | Confirmed work email and phone |
| Business legitimacy | Is this a genuine business or agency? | Registration details, website and domain match, public presence |
| Representative authority | Is this person entitled to act for the business? | Work email on the business domain, confirmation from the business |
| History | Has this business behaved well on the platform? | Completed bookings, reports, payment record |
Each check has its own status, its own date and its own rules for when it expires or must be repeated. A profile can be contact-verified and identity-verified while portfolio review is still pending. That is fine, as long as the profile says so.
Identity verification without collecting too much
Identity verification is the check that people worry about most, and rightly so. It involves sensitive documents. Done carelessly, it creates a store of identity data that is valuable to attackers and unnecessary for the business.
The principles we apply:
- Collect for a purpose, keep for a limited time. The platform needs to know that a person is real and matches their profile. It does not need to hold a copy of their passport indefinitely once that is established. We keep the verification result and the minimum record needed to show that it happened, and delete source documents according to a written retention schedule. See Data retention and deletion.
- Separate the evidence from the profile. Identity documents are held apart from profile data, with much tighter access. Staff who moderate portfolios cannot open identity files. See Least-privilege access for small teams.
- Show the result, not the evidence. Brands see that identity has been verified. They never see the document, the document number or the date of birth.
- Use specialist processes where appropriate. Identity checks involve fraud patterns that are hard to detect by eye. Where a specialist verification process is used, it is chosen for its data handling as much as its accuracy, and it sits behind CastLyra's own boundary.
Age deserves particular care. Some creative work involves people under 18, and many legal systems set specific rules for young performers and for their images. Where under-18 talent is involved, a parent or guardian must be part of the account and consent process, and access and contact rules become stricter. The principles behind that are covered in Child data minimisation in edtech, and although that article is about education, the same instinct applies: collect less, restrict more, involve the responsible adult.
Portfolio ownership: the hardest check
Proving that someone is a real person is comparatively straightforward. Proving that the work they show is theirs is harder.
For models and on-camera talent, the question is whether the person in the images is the account holder. For photographers, stylists and other creative professionals, the question is whether they actually made or contributed to the work. For creators, it may be whether the channel or content they point to is genuinely under their control.
There is no single test. We combine several signals:
- Likeness consistency between identity verification and portfolio images, reviewed by a person.
- Source evidence, such as original files, credits, published work with the person named, or links to channels where control can be demonstrated (for example by posting a short code).
- References from previous clients or collaborators, where the talent chooses to provide them.
- Inconsistency flags, such as images that appear elsewhere under another name, or a portfolio whose style and quality shift abruptly.
AI can help here, but in a limited way. It can help structure a profile from what the talent provides, suggest missing information and flag possible inconsistencies for a reviewer. It does not decide that a portfolio is genuine or fake. That follows the group principle that AI explains, verified data decides, and in this case the verified data is evidence a person has looked at. Generated profile text is also validated so it never invents credentials, clients or awards the talent did not supply; see Structured outputs and schema validation.
Consent is part of verification
Creative portfolios contain images of people. Sometimes those people are the talent themselves. Sometimes they are other models in a shoot, or members of the public in the background, or clients whose products appear. Showing those images on a marketplace is a use that needs a basis.
CastLyra treats consent as a verification topic, not just a terms-of-service clause:
- Talent declares rights for each portfolio item: that they appear in it with consent, or have permission from the people and rights holders involved.
- Photographers and creatives declare that they have the right to display the work, which may depend on their agreements with clients.
- Takedown is fast. Anyone who appears in an image and did not consent to its use on CastLyra has a clear route to request removal, and requests are handled promptly by a person.
- Use on the platform is limited to the platform. A brand browsing talent is not being granted a licence to reuse portfolio images. Any use beyond viewing is a matter for a direct agreement.
There is also the consent the talent gives to CastLyra itself: to be listed, to be contacted by verified businesses, to receive product messages. That is separate from any marketing consent, and treated separately; see Marketing consent vs product consent.
Contact details: released by rules, not by default
Verification only protects people if it controls what happens next. A marketplace that verifies everyone carefully and then displays phone numbers and email addresses publicly has done half the job.
On CastLyra, talent contact details are not shown on public profiles. Access follows rules:
- A business must be verified to a defined level before it can send a message or booking request through the platform.
- Talent choose whether to accept a conversation.
- Direct contact details are shared only when the talent chooses to share them, or at a defined point in a confirmed booking.
- Unusual patterns, such as one account messaging many talent in a short time with similar text, trigger review.
This design also affects CastLyra's AI features. Talent contact details are kept out of AI prompts entirely, so no model call can accidentally surface them.
Trust signals: showing verification honestly
Verification is only useful if people can see and understand it. We present trust signals as specific statements, each tied to a check:
- "Identity verified" with the month it was completed.
- "Portfolio reviewed" with the month, or "Portfolio review pending".
- "Business verified" for companies, with the business name as registered.
- Booking history, shown as counts rather than stars where the sample is small.
We avoid signals that sound stronger than the evidence. A profile that has passed contact verification only does not get a badge that implies more. Ratings are only shown once there are enough of them to mean something, and they are tied to completed bookings, not open-ended reviews anyone could leave.
We also explain what each signal means in plain language, one click away. Brands and talent should not have to guess what "verified" covers.
When verification fails or changes
Checks do not last forever, and some fail.
- Expiry. Identity verification is repeated after a defined period or when key profile details change, such as a legal name.
- Failed checks. A person whose identity cannot be verified can still hold an account in a limited state but cannot receive booking requests. The reason is explained, and there is a route to try again or to speak to a person.
- Reports. Any user can report a profile or a business. Reports go to a person, not an automated verdict, and serious reports (suspected impersonation, unsafe requests) are prioritised. The pattern is described in Human escalation in AI products.
- Revocation. If evidence emerges that a verification was wrong, the status is removed promptly and anyone who interacted with that account in a booking is informed where appropriate.
The cost of verification, and who pays
Good verification is not free. Identity checks, human portfolio review, business checks and report handling all cost time and money, and they happen before any revenue from that user.
Three decisions shape how this is handled:
- Staged verification. Not every check needs to happen at sign-up. Contact verification comes first; identity before a profile is shown to brands; portfolio review before a profile is promoted or appears in certain categories. That spreads cost and reduces friction for people who are just exploring.
- Verification as part of the offer. For businesses, verification is part of what gives them access to talent, so it sits naturally inside paid plans or booking fees. How that fits different revenue models is discussed in Marketplace monetisation models.
- Unit cost tracking. Verification cost per active profile is one of CastLyra's unit economics lines. See Unit economics per product.
Verification also slows early growth. A marketplace that verifies strictly will have fewer profiles at launch than one that accepts everyone. We think that is the right trade, and we discuss how to handle it in Solving the cold-start problem.
A scenario: a suspicious casting request
Imagine a newly registered business on CastLyra that passes account verification and then, within an hour, sends near-identical messages to dozens of models, offering high fees for a shoot in a private location and asking them to continue the conversation on a personal messaging app.
What should happen:
- The volume and similarity of messages trigger a review flag.
- The business's legitimacy check has not yet been completed, so messages are held rather than delivered in full.
- A reviewer looks at the account, the business details and the message content.
- If the business cannot be verified, the account is restricted and the messages are not delivered. Any models who did receive an early message are warned.
- The pattern is recorded so similar attempts are caught faster.
None of this requires a model to make a judgement about intent. It requires clear rules, sensible thresholds and a person with the authority to act.
Different talent, different evidence
A global creative marketplace covers very different kinds of work, and the same check does not fit all of them. Treating a fashion model, a video creator and a set designer identically either makes verification too heavy for some or too light for others.
- Models and on-camera talent. Likeness is the core of the work, so the link between identity verification and portfolio images matters most. Measurements and physical details, where talent choose to show them, are self-declared and labelled as such.
- Creators. Control of the channels they point to is often the most meaningful check. A short code posted to a channel and then removed is a simple, low-intrusion way to show it.
- Photographers, stylists, make-up artists and other creative professionals. Credits and published work carry more weight than likeness. A named credit in a published editorial or campaign is stronger evidence than an unlabelled image.
- Agencies representing talent. Here the question shifts to authority: is the agency entitled to represent the people it lists, and do those people know they are on CastLyra? Each represented person should be able to see and control their own profile.
Writing these differences down, per category, keeps reviewers consistent. Two reviewers looking at the same kind of profile should reach the same decision for the same reasons.
Measuring whether verification works
Verification is easy to describe and harder to evaluate. A system that rejects nobody looks efficient and may be useless. A system that rejects many may be protecting people or may be turning away genuine talent.
The measures we watch for CastLyra:
| Measure | What it tells us |
|---|---|
| Time from sign-up to each verification level | Whether the process is too slow for genuine users |
| Share of profiles that stall at each stage | Where friction or confusion sits |
| Reports per active business and per active profile | Whether bad actors are getting through |
| Reports upheld after review | Whether reporting is being used fairly |
| Verifications later revoked | Whether checks are catching what they should |
| Talent-reported unsafe contact attempts | The outcome that matters most, which we want as close to zero as possible |
We review these regularly and adjust thresholds, evidence requirements and reviewer guidance based on what they show, not on a sense that things are probably fine.
Common mistakes in marketplace verification
- One badge for everything. Users read it as the strongest claim.
- Verifying one side only. Talent-side checks without business-side checks leave the more vulnerable party exposed.
- Keeping identity documents forever. Once the check is done, the documents become a liability.
- Publishing contact details. Verification does nothing if anyone can bypass the platform.
- Letting AI decide. Automated verdicts on identity or ownership are hard to explain and hard to appeal.
- Hiding what checks mean. Trust signals that nobody understands do not build trust.
Summary
Verification in a talent marketplace has to run both ways and has to be specific. At CastLyra we separate identity, portfolio ownership, consent and business legitimacy into distinct checks, show each one honestly with a date, keep identity evidence apart and for a limited time, release contact details only by rule, and keep AI in a supporting role while people make verification decisions. It costs more and grows more slowly than accepting everyone. It is also the only way a marketplace for creative talent can deserve the trust of the people on both sides of it.
Questions and answers
What does verification mean in a talent marketplace?
It means confirming that a person or business is who they claim to be and that what they show is genuinely theirs. In a talent marketplace that usually covers identity, portfolio ownership, image consent and, for hiring businesses, legitimacy.
Does CastLyra verify brands as well as talent?
Yes. Talent is at real risk from fake castings and bad actors, so businesses that want to contact or book talent go through their own verification before gaining that access.
Can AI verify a person's identity or portfolio on its own?
At CastLyra, no. AI helps structure profiles and flag possible inconsistencies, but verification decisions are made from evidence and reviewed by people.