Account security playbook
Welcome the customer. Not the impersonator.
Start by establishing what a normal session looks like for your own product. At login, verify the request on your server and compare the returned device context with the account’s recent history. A new device is not inherently suspicious; combine it with automation indicators, inconsistent environments, and account behavior before adding friction. Use step-up verification for uncertain sessions, keep an auditable reason for the decision, and give legitimate customers a recovery path. Monitor outcomes before turning a new rule into a hard block.
- Steps
- Recognize returning device contextSurface unusual access patternsAdd verification only when needed
