{
  "id": "XBC-007",
  "slug": "xbc-007",
  "title": "A public company must finish two-factor identity before any campaign",
  "statement": "A PUBLIC_PROFIT brand must complete its Authentication+ two-factor identity step before a campaign is created against it.",
  "rationale": "Publicly traded brands carry an extra identity step that no other entity type has, and it is the one gate that produces no error while it is outstanding: the brand verifies, looks healthy, and every campaign against it is refused. The two-factor mail goes to the business contact address, so it is routinely missed by the person doing the registration, who is rarely the person on that mailbox.",
  "layer": "CROSS",
  "layerSlug": "cross",
  "object": "brand.entity_type + brand.vetting + campaign submission",
  "severity": "BLOCKING",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "TCR"
  ],
  "applicability": {
    "entityTypes": [
      "PUBLIC_PROFIT"
    ]
  },
  "applicabilityText": "Applies when the brand is a public company.",
  "universal": false,
  "dependsOn": [
    "XBC-006"
  ],
  "remediation": "Order the Authentication+ vet explicitly after the identity check, watch the business contact mailbox for the two-factor mail, and hold the campaign until the vet is recorded on the brand. Done when the brand shows an Authentication+ vet before the campaign is submitted.",
  "notes": "The vet is an action at the registry, not a field on the submission, and the PIN arrives by mail on the registry's schedule. What the user has to do is confirm who receives the business contact mail and that they know to expect it — BRD-225 covers ordering the vet, BRD-226 the window it must be completed in; this rule is the campaign-side consequence of either being outstanding.",
  "catalogIds": [
    "OPS-311"
  ],
  "phase": "approval",
  "automated": true,
  "attestation": {
    "question": "Do you know who receives mail at the business contact address, and that they are expecting the Authentication+ two-factor message?",
    "howToCheck": [
      "Name the person on the business contact mailbox out loud. It is rarely the person doing the registration.",
      "Tell them the two-factor mail is coming and what to do with it, then confirm the completed vet appears on the brand before submitting the campaign."
    ],
    "failureLooksLike": "The brand verifies and looks healthy, every campaign against it is refused, and the two-factor mail is unopened in a shared inbox nobody watches."
  },
  "url": "https://ekas.io/rules/10dlc/cross/xbc-007/",
  "markdown": "https://ekas.io/rules/10dlc/cross/xbc-007.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
