Authentication and application authorization stay separate. OIDC proves identity; persons.role and Project
participation decide access. OIDC_DISABLED exists for host-side diagnosis but the deployment invariant rejects it in
both parsed profiles. NAVIGATOR_GCP_METADATA_ENDPOINT, GOOGLE_TOKENINFO_URL, and
NAVIGATOR_IDENTITY_PLATFORM_ENDPOINT are controlled test seams; a normal deploy leaves them on their secure defaults.
NAVIGATOR_BOOTSTRAP_COMPANY names a firm Entity that lawyer and admin may re-type or re-domicile but never rename or
delete. It adds to rather than replaces the protected set: the canonical seed re-creates Shook Law PLLC by exact name
on every boot, so that row is protected in every deployment and a white-label operator's own firm Entity is protected
alongside it.