Protected route
Admin access needed
This workspace controls provider setup, security, QA, monitoring, or platform operations. Learner mode can inspect the denial state, but cannot open the admin surface directly.
Audit behavior
Denied attempts are stored
Writes an auth dry-run record to the runtime store.
Admin Ops shows route policy health, session role, and dry-run count.
Production provider setup still requires real auth credentials.