Auth readiness
Real customer accounts should be a launch priority, not an afterthought.
TAVALIS needs a live sign-in path that keeps customers inside one structured platform from intake through documents, billing, and ongoing company operations.
The target shape is invitation-based, portal-native, and aligned with later role-aware document access. Production switch-on remains intentionally blocked until Guido approves the exact provider and rollout path.
Prepared tracks
Identity anchor
PreparedCustomer access should center on one verified email identity with invitation-based account creation.
Session hardening
PreparedLater live auth should expose device/session review, magic-link or passwordless entry, and stronger recovery controls.
Portal permissions
PreparedDocuments, billing, messages, and tasks need role-aware visibility instead of one flat access layer.
Invite and seed model
PreparedSeeded portal principals and invitation records should exist before broader customer activation starts.
Production switch-on
Blocked pending GuidoReal customer authentication remains intentionally off until the provider, policy, and rollout path are approved.
