01
Separate trust zone
The privileged-access tier is its own network, its own listener, its own auth path. A phished routine session cannot reach a destructive route — the origin returns 403 unless the request arrived on the privileged tier. Stronger than step-up re-auth: the path simply does not exist on the routine tier.