• Auth flow: work-email check → client-domain match → MFA
• Role-based UI across 7+ roles — employee, manager, billing, HR, admin, super admin, client admin
• Roles stored as custom claims, set by a backend function only after it validates the data
• Every protected action checked against both the auth claims and the stored record
• Writes only through API routes with verification and idempotency; database rules as a second layer
• Paid certifications on Stripe: verified webhooks, deduplicated events, idempotent processing