Direkt zum Security-Inhalt
Auth readiness

Real customer accounts should be a launch priority, not an afterthought.

TAVALIS needs a live sign-in path that keeps customers inside one structured platform from intake through documents, billing, and ongoing company operations.

The target shape is invitation-based, portal-native, and aligned with later role-aware document access. Production switch-on remains intentionally blocked until Guido approves the exact provider and rollout path.
Prepared tracks
Identity anchor
Prepared
Customer access should center on one verified email identity with invitation-based account creation.
Session hardening
Prepared
Later live auth should expose device/session review, magic-link or passwordless entry, and stronger recovery controls.
Portal permissions
Prepared
Documents, billing, messages, and tasks need role-aware visibility instead of one flat access layer.
Invite and seed model
Prepared
Seeded portal principals and invitation records should exist before broader customer activation starts.
Production switch-on
Blocked pending Guido
Real customer authentication remains intentionally off until the provider, policy, and rollout path are approved.
Verified email identity as the customer account anchor
Portal permissions for documents, billing, messages, and tasks
Seeded principal + invite record before customer activation
Later session/device visibility before broader scale-up