TL;DR: For a B2B SaaS login without webhooks, keep the signup verification message in the application repository when product engineers own the flow, then use bounded polling for SMS OTP delivery status. Treat that status as operational evidence, not proof that a person received or read the code. Stop querying, let the code-entry screen remain usable, and offer a controlled resend when the window ends. Template owner Pick this when Main trade-off Status strategy Applic...