Identity controls
The platform supports tenant-scoped auth, MFA, MFA recovery, SSO, sessions, refresh-token rotation, and API keys. These controls must be consistent across admin and portal surfaces.
Governance controls
Audit logs, incidents, privacy, retention, step-up enforcement, and permission-scoped operations are part of the expected platform posture.
Launch-critical control contracts
Public mutating auth requests must enforce idempotency, and privileged SSO logout must complete both local logout and upstream provider logout.
Source Documents
- Launch Audit: docs/auditreport.md
- Launch Recommendations: docs/recommendations.md