Login as a state machine
Treating sign-in as one method means every new requirement becomes another conditional. Modelling it as states made multi-factor readiness a matter of inserting a step, and made the flow explainable to non-engineers on a whiteboard.