AD-07 · Identity / Session Architecture.
Defining who controls user sessions
APPROVEDSUPPORTED
- The decision
- Explicitly assign a session authority and separate the session lifecycle from the authorization to operate on financial systems.
- Why it mattered
- A user can sign in from several devices or channels, and the platform has to decide which sessions may coexist, which ones get replaced and how they are revoked.
- The trade-off
- A strict policy simplifies some controls but adds friction; allowing concurrency improves the multi-device experience but demands more revocation and monitoring capability.
- What changed
- Session behavior that had been absent from the legacy system was explicitly defined.
Reusable principle
The core must not control digital sessions merely because it is the system of record.
Related transformation
Real-Time Fraud IntegrationSummary of a documented architecture decision. Method, mechanism and supporting evidence are not published.