This runs once. We will create the protected platform account, bind it to the internal platform org, and lock future platform access to that explicit identity.
After this, sign in at admin.ladra.app, finish MFA, add a passkey, and this bootstrap path will close.