Authentication and Sessions
Password authentication, configurable MFA/TOTP, session and token controls, account lifecycle functions, and SAML/OIDC configuration paths exist in the application.
Validation boundary
Customer identity-provider behavior, MFA policy, break-glass access, logout, deprovisioning, rotation, and hosted configuration require environment-specific validation.