Skip to secure gateway

Separate authenticated boundary

Access follows position, purpose and time.

Marketing trust does not become application trust. The production experience would use tenant-safe discovery, federated identity, MFA, lifecycle signals and server-side authorisation at every data and action boundary.

  • No tenant enumeration
  • No credentials in URLs
  • No marketing tracking
  • Time-bound privilege
  • Logged recovery
  • Purpose re-check

Sign in

Synthetic

Reference flow

A second factor would be required by tenant policy, with step-up for sensitive purposes and break-glass recorded separately.

  • Authenticator app
  • Hardware key
  • Approved fallback
  • Identity re-proof
  • Named approver
  • Time-bound token
  • Audit event written

Tenant discovery and the sign-in above are real. MFA and recovery are described here but not implemented — a tenant's own identity provider would enforce them.