Break-glass and ownership
- Owner break-glass. The team owner always keeps password login, and break-glass use is logged.
- Local two-factor. Still applies to password and break-glass logins when set up. Skipped for SSO sessions, where the IdP enforces MFA.
- Domain proof. DNS TXT verification before SSO. One team per domain, and no public email domains.
- Certificate rotation. Two certificates are accepted during a rotation. The owner is notified 30, 14 and 7 days before expiry.