net-kingdom/workplans/NK-WP-0042-workload-mfa-step-up.md

54 lines
1.6 KiB
Markdown
Raw Normal View History

---
id: NK-WP-0042
type: workplan
title: "Let workloads require MFA for all or part of their features"
domain: infotech
repo: net-kingdom
status: proposed
flavor: planning
owner: claude-code
topic_slug: netkingdom
created: "2026-09-23"
updated: "2026-09-23"
related: [NK-ADR-0016, NK-WP-0037]
---
ADR-0016 makes MFA a user preference by default and lets a workload require
it for all or some of its features. This workplan defines how a workload
states that requirement and how the flow enforces it. It does not require MFA
anywhere; the enrollment and recovery usability gate in ADR-0016 still
applies first.
## Specify the workload-requested step-up contract
```task
id: NK-WP-0042-T01
status: todo
priority: medium
```
Define how a workload requests AAL2: per client registration for the whole
feature set, or per request as a step-up when a protected feature is used.
Specify:
- which OIDC parameter the request uses (`acr_values`, `max_age`, or both);
- what KeyCape must return when a user has no factor (a clean refusal and an
enrollment route, never silent AAL1);
- how the resulting `assurance.level` reaches flex-auth.
Record it as an IAM Profile amendment. key-cape owns the implementation.
## Agree the user-facing step-up and enrollment journey
```task
id: NK-WP-0042-T02
status: todo
priority: medium
```
With user-engine (U06, factor recovery) and one pilot workload, agree what a
user sees when a feature needs MFA and they have none. That includes the
enrollment detour, the return to the feature, and recovery. It must be
accepted from a user's perspective before any workload turns the requirement
on.