Security
We addressed a risk even though it was not part of the brief
The initial solution included custom multi-tenant sign-in built on AWS Cognito.
During analysis we identified risks in how individual customer organisations were separated. We described the problem, proposed changes and, together with the client, included them in further development.
It was not a feature visible on screen.
It was, however, something that could decide whether the product could be operated safely for multiple financial institutions.
Responsibility for the product does not end at the boundary of the original backlog.
