RequirementPreview contractOwning surfacePrimary gateAcceptance evidence
AUTH-001AUTHHuman identity and tenant membership are separate scoped recordsCONFIGURATIONsettingsGate 6G03-COV-AUTH-001AUTH-002AUTHPasskey-preferred privileged authenticationCONFIGURATIONsettingsGate 6G03-COV-AUTH-002AUTH-003AUTHMandatory MFA boundaries for platform and high-risk tenant rolesCONFIGURATIONsettingsGate 6G03-COV-AUTH-003AUTH-004AUTHApproved MFA factors, single-use recovery codes, and no security questionsCONFIGURATIONsettingsGate 6G03-COV-AUTH-004AUTH-005AUTHNIST-aligned password defaults and Argon2id storageCONFIGURATIONsettingsGate 6G03-COV-AUTH-005AUTH-006AUTHLogin rate limiting, stuffing detection, generic errors, and risk challengesCONFIGURATIONsettingsGate 6G03-COV-AUTH-006AUTH-007AUTHRegistered POS device + unique device-bound employee PIN; no shared cashierCONFIGURATIONsettingsGate 6G03-COV-AUTH-007AUTH-008AUTHOS/device biometric use without cloud raw biometric templatesCONFIGURATIONsettingsGate 6G03-COV-AUTH-008AUTH-009AUTHStaff/owner/platform recovery and 24-hour high-risk contact-change cooling defaultCONFIGURATIONsettingsGate 6G03-COV-AUTH-009AUTH-010AUTHServer-side session registry, timeouts, token rotation/reuse detection, and revocationCONFIGURATIONsettingsGate 6G03-COV-AUTH-010AUTH-011AUTHTrusted-device lifecycle, remote revoke, and unsynced-event-safe lost-device handlingCONFIGURATIONsettingsGate 6G03-COV-AUTH-011AUTH-012AUTHTen-minute recent re-authentication default for sensitive actionsCONFIGURATIONsettingsGate 6G03-COV-AUTH-012AUTH-013AUTHScoped API/device/workload identities with rotation, signing, and revocationCONFIGURATIONsettingsGate 6G03-COV-AUTH-013