Customizing Ash Authentication (Not UI Layer)

I wouldn’t be too attached to AshAuthentication. AshAuthentication is a way for us to provide pre-built variations of authentication easily. There is nothing wrong with using “regular” actions/resources and powering the flow yourself. You can very likely make modifications to the actions that underpin AshAuthentication, (i.e you should see actions in your user resource like sign_in_with_password and register_with_password that you are free to customize, thats why we generate them into your app), but at the end of the day if you’re worried about being able to rigidly prove that your app behaves to some specific requirement or specification, you may be better off not using AshAuthentication at all. Perhaps it just adds value while prototyping and later you replace it with your own tooling etc.