- The operator's Vergabe recipient journey completed after the KeyCape fresh-login fix: sign-in, callback and account confirmation. - ADR-0016 records MFA as user preference by default, workload-requested step-up for all or part of a feature set, and an unchanged IAM v0.3 floor. - NK-WP-0042 (proposed) plans the step-up contract and user journey. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 299762@bnt-lap001 Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
1.6 KiB
| id | type | title | domain | repo | status | flavor | owner | topic_slug | created | updated | related | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| NK-WP-0042 | workplan | Let workloads require MFA for all or part of their features | infotech | net-kingdom | proposed | planning | claude-code | netkingdom | 2026-09-23 | 2026-09-23 |
|
ADR-0016 makes MFA a user preference by default and lets a workload require it for all or some of its features. This workplan defines how a workload states that requirement and how the flow enforces it. It does not require MFA anywhere; the enrollment and recovery usability gate in ADR-0016 still applies first.
Specify the workload-requested step-up contract
id: NK-WP-0042-T01
status: todo
priority: medium
Define how a workload requests AAL2: per client registration for the whole feature set, or per request as a step-up when a protected feature is used. Specify:
- which OIDC parameter the request uses (
acr_values,max_age, or both); - what KeyCape must return when a user has no factor (a clean refusal and an enrollment route, never silent AAL1);
- how the resulting
assurance.levelreaches flex-auth.
Record it as an IAM Profile amendment. key-cape owns the implementation.
Agree the user-facing step-up and enrollment journey
id: NK-WP-0042-T02
status: todo
priority: medium
With user-engine (U06, factor recovery) and one pilot workload, agree what a user sees when a feature needs MFA and they have none. That includes the enrollment detour, the return to the feature, and recovery. It must be accepted from a user's perspective before any workload turns the requirement on.