The signals
Each of these is worth one point, judged against your last 50 successful sign-ins. With 2FA on, a sign-in only counts as successful once the code was accepted, so a device that got past your password but not the code never becomes a known one:
Two points locks the account. The new-country signal only counts once Meridian has a country recorded for you at all, and a first-ever sign-in never triggers any of this, because with no history there is nothing to look anomalous against.
Passkeys are scored differently
A passkey is bound to the device it lives on, so the new-device signal is not counted for it and the threshold rises to three. A phishing-resistant credential should not lock you out because your phone changed IP on the train.What a lock looks like
No session is created, and the attempt is recorded in your login history as Blocked: suspicious. Every further attempt while the lock holds is recorded as Blocked: locked. Meridian emails the account address with two ways to approve, both good for 15 minutes:- an Approve link, and
- a 6-digit code to enter.
Getting back in
Approve the challenge and sign in again, or reset your password. A reset proves control of the same email the approval was sent to, so it clears the lock on its own, and it expires any unused challenge, so an old approval message cannot be used afterwards.What this is not
This is not protection against password guessing. Repeated wrong passwords are handled by rate limiting, and locking an account on failed attempts would let anyone lock you out on purpose. The lock here applies only once credentials have succeeded and the session still looks wrong, which is why a burst of failed guesses is one input to the score rather than a trigger of its own.Turning on 2FA is the stronger control: it stops a stolen password being enough in the first place, rather than catching it afterwards. The two work together: risk scoring runs whether or not 2FA is on.