Why we ask for a code before refunds and payout changes
A handful of actions move or redirect money, and for those Turtini asks you to confirm a code even though you are already signed in.
**Which actions**
- Issuing a refund of **$100 or more**.
- Changing the bank account your payouts or paychecks go to.
- Changing where a vendor's payments are sent.
- Running a payroll payout.
- Sending money to another person above $100.
- Rotating a kiosk token, or removing a saved card.
- Releasing funds that are being held back.
**Why, when you already signed in**
Being signed in proves the session is valid. It does not prove *you* are the one using it. An unlocked laptop, a phished login, a shared device — at every other screen that difference does not matter much, and at these screens it is the whole thing. Changing a payout bank account redirects every future paycheck, and the person it belongs to would not find out until payday.
**How it works**
1. You do the action as normal.
2. Turtini asks you to verify — with your authenticator app, a code by text, a phone call that reads the code out, or a recovery code if you have lost your device. These are the same choices you get when signing in on a new device.
3. Enter the code and the action goes through. You never re-enter the details.
**Read what it says before you type anything.** The prompt names the exact action and amount. **If a verification prompt appears when you did not just do something, do not enter a code** — cancel, change your password, and tell your organization's owner. That prompt appearing on its own means someone else is using your session.
Each verification covers exactly one action, once, and expires after ten minutes. Verifying a $40 refund cannot be turned into a $4,000 one, and it cannot be reused for a different organization.
**No phone number on your account?** The text and call options need one. Add it in **Account -> Profile**, or set up an authenticator app under **Account -> Security**, before you need it.