Y-Statement (structured decision record)
Sentence
In the context of product authentication and limited platform headcount, facing building and operating login, MFA, OAuth, and session security in-house, we have decided for a managed identity provider for interactive login and standard OAuth flows in order to ship secure login and compliance-friendly posture without owning the full auth surface, accepting that vendor cost, less exotic customization, subprocessors in our compliance pack.
Fields (same content, for reviews)
- Context: product authentication and limited platform headcount
- Concern: building and operating login, MFA, OAuth, and session security in-house
- Stance / subject: for / a managed identity provider for interactive login and standard OAuth flows
- Intended outcome: ship secure login and compliance-friendly posture without owning the full auth surface
- Deliberate tradeoff: vendor cost, less exotic customization, subprocessors in our compliance pack