The panel
- Unprivileged web tier; root work only through typed agent operations
- Deny by default on every method and path
- Passkeys, Argon2id passwords, authenticator and recovery codes
- Two-step sign-in required for administrators and resellers
- Step-up for high-risk actions, session rotation
- Device list with instant sign-out; scoped, revocable API tokens
- Hash-chained audit log with verification
- Single sign-on (OIDC and SAML) (coming soon)
- Sign-in anomaly alerts (coming soon)
- An external anchor for the audit chain (coming soon)