Different roles and their access levels to the system were defined. Access control was discussed.
A07:2021-Identification and Authentication Failures
Identification and Authentication credential was identified to be email. It was discussed that no default or unsecure credentials should be deployed to the final product.
Authentication was decided to be left to third party platform. It was discussed that no default or unsecure credentials should be deployed to the final product.