Accès par organisation
Every surface uses the organization context and authorized role.
ONZARIS / TRUST
OBSERVED CONTROLS
Every surface uses the organization context and authorized role.
Sensitive decisions keep an actor, target and timestamp.
The admin space supports TOTP MFA and recovery codes.
Player/parent journeys remain separated and contextualized.
No provider token or external write is enabled implicitly.
Web surfaces are checked across personas and formats.
WHAT STILL NEEDS PROOF