OPS identity now supports bounded local password auth and an optional signed-proxy enterprise identity bridge. Sensitive reports, PRE/PAR write actions, and admin surfaces still require an authenticated app session either way.
Bootstrap admin setup is internal-only. No hardcoded credentials or silent universal bypass are provided.
A bootstrap user already exists or local bootstrap is disabled.
Bounded app auth and RBAC only. Live support in this phase includes local password auth and an optional signed-proxy enterprise identity bridge. This is not blanket enterprise SSO certification, not direct OIDC/SAML login inside the app, not a bank workflow, and not an approval signal.