Are there downsides to doing this? This was my first thought - though I also recognize that first thoughts are often naive.
You don't want "project had X users so it's less safe" to suddenly transition into "now this software has X*10 users so it has to change things", it's disruptive.
TOTP although venerable was better than no second factor at all.
You don't want "project had X users so it's less safe" to suddenly transition into "now this software has X*10 users so it has to change things", it's disruptive.