qbflow Auth policy console
Draft UI — named sign-in policies, reusable factor bundles, "what would this employee be asked", audit ·
Sign-in experience → ·
app ships Russian; this draft is English for review
Sign-in policies
Factor bundles · mapped to assurance level
Roaming FIDO2 key (YubiKey), attestation. Phishing-resistant.
AAL3
Passkey (Windows Hello / Touch ID), origin-bound. + recovery codes.
AAL2
Password + TOTP. Legacy fallback, phishable.
AAL2
What would this employee be asked?
Pick an employee — see the resolved factors and which rule wins
m.ayoub — Admin
e.nuriev — Warranty
a.leonov — Sales (lead)
i.smirnov — Assembly
k.orlov — Accounting (no specific rule)
Warranty & Sales — Phishing-resistant
Department scope · click factors to change. Server re-validates; the lockout guard blocks a save that would brick everyone.
Name
Report-only mode logs what would be enforced without blocking anyone — roll a stricter policy out safely first.
Audit