The problem as published
A retail giant with stores, distribution centers, and online platforms needs employees to reach many systems daily. MFA improves security but adds friction and support load; SSO reduces prompts but still issues reusable sessions and tokens that, once stolen, work until expiry.
How ENI6MA would apply
ENI6MA would sit behind the existing SSO IdP: human login still federates once, but applications that change inventory, payments, or PII would require Gate-enforced envelopes from Pass+ or SDK middleware. Shadow mode would let security observe envelope coverage before cutting over high-risk apps to proof-required.
Expected outcomes if implemented
- Would keep single-sign-on convenience while retiring reusable tokens on the routes that move money or PII.
- Would cut helpdesk MFA reset load on paths migrated to one-shot proofs.
- Would give operators a per-endpoint migration dial rather than a big-bang cutover.
Reference architecture
Gate: SDK middleware + Pass+ for human paths · Circuit: standard / hybrid · Migration: shadow mode then proof-required
Absolute mechanism claims hold under the reference architecture.
