Internal directory only. Broker accounts cannot sign in here — they use the broker door.
Hardware key required. There is no password field and no SMS fallback. A staff session can act inside any brokerage, so the second factor is a physical key rather than something that can be phished or intercepted.
Everything you do here is written to the audit log with your name against it, including read-only access to a brokerage’s data. ← Broker sign-in
Prototype. No key is checked. Continue to open the admin console. In production this sits on its own hostname behind an IP allowlist.