Use when
- Users have submitted credentials or authenticator output and need a safe verification result.
- The product has failed-attempt counters, throttling, lockout, unlock, or risk-based login states.
- The product must balance brute-force protection, account enumeration prevention, and legitimate recovery.