Whitelabel Global Admin

Private service admin, exposed through a constrained BFF.

This foundation uses Google Auth.js login, an `admin_users` allowlist, Prisma-backed admin authorization, and a protected admin API boundary.

Sign in with GoogleOpen admin shell
Internal service URLs and tokens stay server-side only.