Privileged administrator MFA
Owner and administrator mutations require an AAL2 authenticator session before sensitive financial, inventory, payroll, user or security changes are accepted.
Enforced in the application session and PostgreSQL control path.