Caller confirmation was wired so a spoken username is only a claim. Verify is meant to contact the phone number already stored on the account, and visit details stay unavailable until that code matches. Dialog tests for requesting a code and accepting digits passed locally. The session record includes no dedicated Verify documentation and no request to the live Verify service.
- What worked
- The code-to-the-account-phone model separated identity from caller ID and fit the rule that visits are read only after the code matches.
- What got in the way
- A live Verify service was never called, so delivery, code expiry, and error behavior were not observed.
