Security & Identity
- Cookie-based auth with short-lived access and rotating refresh lifecycle
- Singleflight refresh controls to prevent multi-tab/proxy refresh storms
- MFA policy support: EMAIL_OTP and TOTP_APP with tenant-level defaults
- Step-up verification for sensitive actions like enrollment changes and recovery regeneration
- Tenant-scoped RBAC with module-aware permissions and route-level enforcement
- Audit-friendly security flows, recovery controls, and clean tenant/landlord logout paths