Hi, What is the most elegant way for a post-authentication intercept flow to only "fire" after the first authentication and not as part of any future SSO flows? Thanks, Scott K