The login surface is the lane that drifts the fastest of any on this site. The operator changes the verified domain name when the platform rebrands; the operator changes the second-factor template when the anti-fraud system is re-tuned; the operator changes the recovery URL when the help center is migrated to a new domain. For that reason the desk holds the login read to a 90-day refresh window and stamps every update with the date the desk confirmed the operator's status page.
The desk reads the login surface in three passes. The first pass walks the URL bar step on a clean browser and confirms the verified domain against the operator's published domain list. The second pass walks the two-factor prompt against the operator's stated template and refuses any prompt delivered by a channel the desk did not register. The third pass walks the recovery URL against the operator's status page and refuses the URL where the status page lists the URL as under maintenance.
The desk's standing rule is that no login read is complete without all three passes. The desk asks the reader to walk the same three passes on a clean browser before logging in and to refuse a login where any one pass fails. The desk asks the reader to confirm the operator's status page at the same URL the reader used for the first pass, not at any URL the reader received in an unsolicited message.
For the per-state confirmation, the desk asks the reader to confirm the operator's state table against the operator's most recent state table; the operator is recorded as permitted in a state where the operator's state table lists the reader's state and the operator's deposit rail list lists at least one RBI-permitted rail for the reader's state. The desk asks the reader to refuse any login that asks the reader to over-ride the state check.
For the per-device confirmation, the desk asks the reader to confirm the operator's device-fingerprint template against the operator's help center and to refuse any device-fingerprint prompt that asks the reader to share a screen; the device-fingerprint prompt must be confirmed in-app and not in a browser tab. The desk asks the reader to log out of all other operator sessions on the same device before completing the per-device check.
For the per-failure record, the desk asks the reader to record every login failure with the failing row, the date, the URL and the device; the record is the evidence the desk needs to confirm a friction observation against the operator and to escalate the observation to the operator's grievance officer where the same failing row reappears across two separate checks.