Every transaction rests on an assumption that the parties are who they say they are. Verification makes that checkable — and the design problem is proving enough without collecting more than anyone should be holding.
Different actions need different confidence, and requiring the strongest check for everything excludes people who would comfortably pass a proportionate one. The ladder runs from a confirmed email through a document check to an enhanced screen, and an action asks for the level it actually needs.
A check the subject can pass by asserting it is not a check. On this protocol nobody approves their own verification — including administrators — and every decision records who made it and why. A refusal requires a stated reason, because a rejection nobody can act on is a dead end rather than a decision.
When a provider returns a status the code does not recognise, it resolves to pending. Failing toward "not yet verified" is recoverable; failing toward "verified" is a person who was never checked walking through a gate.
Identity is not permanently true. Watchlist and background checks have a useful life, after which an unrepeated check is an assumption wearing the clothes of a fact — so they expire and ask to be repeated.