Defines storage, endpoints, events, error handling, monitoring, and support procedures for suspicious login detection. This reference fixes the adoption boundary, failure behavior, and observable evidence while leaving environment-specific limits configurable.