Public and research-sector systems often involve multiple organizations, roles and projects. Login alone is not enough.
Role-based access control, project-level permissions and administrative audit logs protect sensitive data and execution rights.
A clear authentication model helps the system keep security boundaries as the product grows.