Skip to content

ADR-0005: Login-Required and MFA Enforcement

  • Status: Accepted

Context

OpenSESA handles governance and assurance data requiring stricter access posture.

Decision

Enforce login globally and apply MFA requirements via middleware-based controls.

Consequences

  • stronger baseline security posture
  • auth flow changes require regression testing across all domains