Separate authenticated boundary
Marketing trust does not become application trust. The production experience would use tenant-safe discovery, federated identity, MFA, lifecycle signals and server-side authorisation at every data and action boundary.
Sign in
SyntheticReference flow
A second factor would be required by tenant policy, with step-up for sensitive purposes and break-glass recorded separately.
Tenant discovery and the sign-in above are real. MFA and recovery are described here but not implemented — a tenant's own identity provider would enforce them.