{
  "id": "BRD-228",
  "slug": "brd-228",
  "title": "Do not queue a second Authentication+ vet behind a pending one",
  "statement": "A second Authentication+ vet must not be submitted while one is pending.",
  "rationale": "The second order is refused rather than queued, so the natural response to a vet that seems stuck — order another one — costs a fee and achieves nothing. It seems stuck because the 2FA has not been answered yet, which is a different problem with a different fix.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "the Authentication+ vet queue",
  "severity": "MEDIUM",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR"
  ],
  "codes": [
    {
      "provider": "TCR",
      "code": "525",
      "remediable": true
    }
  ],
  "applicability": {
    "entityTypes": [
      "PUBLIC_PROFIT"
    ]
  },
  "applicabilityText": "Applies when the brand is a public company.",
  "universal": false,
  "remediation": "Check whether the 2FA mail has been answered before ordering anything. If the link has expired, re-request it (BRD-227); if the window has passed entirely, the existing vet has to fail before a new one can be placed. Done when only one Authentication+ vet is in flight.",
  "example": "One Authentication+ vet in flight — chase the 2FA mail rather than placing a second order",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/brand/brd-228/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-228.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
