{
  "id": "BRD-225",
  "slug": "brd-225",
  "title": "Authentication+ must now be ordered explicitly",
  "statement": "Under Authentication+ 2.0 the vet must be ordered explicitly after the identity check; it no longer runs automatically.",
  "rationale": "It used to be automatic, so every runbook, integration and mental model built before the change assumes it will happen on its own. It does not: the brand verifies, nobody orders the vet, and the public-company brand sits without the Authentication+ status that gates its campaigns — with no error anywhere, because nothing failed.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "the Authentication+ vet order",
  "severity": "BLOCKING",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "TCR"
  ],
  "applicability": {
    "entityTypes": [
      "PUBLIC_PROFIT"
    ]
  },
  "applicabilityText": "Applies when the brand is a public company.",
  "universal": false,
  "remediation": "After the identity check completes, place the Authentication+ order explicitly and watch for the 2FA mail. Add the order as a step in your onboarding runbook — its absence produces no error, so nothing will remind you.",
  "notes": "The order is an action at the registry rather than a field on the registration. What the user has to do is remember it: a public brand that verified but was never Authentication+ vetted looks healthy and cannot register campaigns.",
  "phase": "approval",
  "automated": true,
  "attestation": {
    "question": "Has the Authentication+ vet been ordered explicitly, as a step in your runbook, after the identity check completed?",
    "howToCheck": [
      "Open the brand and confirm an Authentication+ order exists. It used to run automatically and no longer does.",
      "Add the order to the onboarding runbook — its absence produces no error, so nothing will remind you.",
      "Then watch the business contact mailbox for the 2FA mail."
    ],
    "failureLooksLike": "The brand verifies and looks healthy. No vet was ordered, every campaign is refused, and nothing anywhere reports a failure — because nothing failed."
  },
  "url": "https://ekas.io/rules/10dlc/brand/brd-225/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-225.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
