If dollars are tight, treat the "platform" as configuration, not code. Extend the SSO/MFA you already own (Shibboleth/AD/Okta) to gate model access; use LMS LTI and existing data connectors before ...