Admin roles & sign-in
Admin is layered as control-plane roles (SecurityAdmin, PolicyAdmin, AuditViewer, EnrollmentApprover, OperationsAdmin) held on top of a normal login. Kicking off a sensitive admin role activates it behind a step-up whose assurance rises with your tier (TOTP at F1, hardware key at higher tiers).
Live today: invite/remove members, author and publish access policy. Coming: the full role model, delegation, and multi-signer approvals.