# BRD-224 — Public companies must clear Authentication+ before campaigns

> A PUBLIC_PROFIT brand must reach identity VERIFIED with Authentication+ ACTIVE before any campaign can be registered.

- **Rule ID:** BRD-224
- **Layer:** Brand (`BRAND`)
- **Checks:** `brand.identity_status`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** External record we cannot query — reported as a warning to verify
- **Fix type:** Wait on an external system or a required interval
- **Required by:** TCR, AWS
- **Applies:** Applies when the brand is a public company.
- **Canonical URL:** https://ekas.io/rules/10dlc/brand/brd-224/

## Why this rule exists

Authentication+ is a two-factor identity confirmation sent to the registered business contact, and it gates campaign creation for public companies specifically. Vendor guidance frequently describes TCR 2FA as universal; AWS is explicit that it applies only to PUBLIC_PROFIT, so applying it everywhere wastes time and applying it nowhere blocks public brands.

## How to fix it

Complete TCR Authentication+ (two-factor identity confirmation) for the brand before submitting campaigns.

## Check this yourself

**Does the brand show identity VERIFIED with an Authentication+ vet recorded as ACTIVE, before any campaign is submitted?**

1. Open the brand record at your provider and read two things: the identity status, and the list of vets attached to it.
2. Confirm an Authentication+ (two-factor identity) vet is present and ACTIVE rather than merely ordered.

*What wrong looks like:* The brand reads VERIFIED and looks finished, but carries no Authentication+ vet. Every campaign against it is refused, and the refusal names the campaign rather than the missing vet.

## Notes

AWS is explicit that TCR 2FA applies only to PUBLIC_PROFIT. Vendor blogs routinely describe it as universal — it is not.
