Control
`POST /v1/control/mfa/enroll`: starts or restarts enrolment.
Available only to a session that has not yet satisfied its second factor, and refused outright once one is confirmed - otherwise anyone who walked past an unlocked screen could quietly replace the second factor with their own.
Errors
Returns 401 without a password-stage session, 409 once a second factor
is already confirmed, and 503 when the enrolment store is unreachable.
POST
`POST /v1/control/mfa/enroll`: starts or restarts enrolment.
Authorizations
A signed-in reviewer's session. httpOnly and SameSite=Lax; set by POST /v1/control/sessions and only usable once the second factor is met.

