{
  "id": "BRD-120",
  "slug": "brd-120",
  "title": "Changing a public brand's contact email resets its identity",
  "statement": "Any change to a PUBLIC_PROFIT brand's business contact email resets identity verification and requires the 2FA to be completed again.",
  "rationale": "The mailbox is the second factor, so replacing it replaces the evidence the verification rests on — the brand drops out of VERIFIED and the Authentication+ state goes with it. Teams make this change for entirely routine reasons, usually when the named person leaves, and discover the brand is unverified only when the next campaign is refused.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "brand.business_contact_email",
  "severity": "BLOCKING",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "TCR",
    "Twilio"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30994",
      "remediable": true
    }
  ],
  "applicability": {
    "entityTypes": [
      "PUBLIC_PROFIT"
    ]
  },
  "applicabilityText": "Applies when the brand is a public company.",
  "universal": false,
  "remediation": "Plan the change: the new contact must be available to answer a PIN within days of the edit, and campaign registration is blocked until they do. Where the change is only a departing employee, prefer a role-independent mailbox on the same domain that a person actually monitors.",
  "notes": "The reset happens at the registry once the change is submitted. What the user has to do is sequence it — make the change when the new contact is at their desk, not during their holiday — because the brand is unverified for the whole gap, and every campaign under it is refused meanwhile.",
  "phase": "approval",
  "automated": true,
  "attestation": {
    "question": "Will the new contact be at their desk and able to answer a PIN within days of this change?",
    "howToCheck": [
      "Sequence the edit around the person: make it when the new contact is available, not the day before their holiday.",
      "Expect the brand to leave VERIFIED and campaign registration to be blocked for the whole gap.",
      "Where the change is only a departing employee, prefer a role mailbox on the same domain that a named person actually monitors."
    ],
    "failureLooksLike": "The contact is updated routinely when someone leaves. The brand is silently unverified, and the team finds out when the next campaign is refused."
  },
  "url": "https://ekas.io/rules/10dlc/brand/brd-120/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-120.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
