Admin access is gated by user_profiles.role = 'admin' only. The permission model is not final: [PLACEHOLDER: ADMIN AUTHENTICATION / PERMISSIONS]
user_profiles rows: display name, role and the company an account acts for. A manufacturer account manages only the company linked here. Emails live in auth.users and are not listed.
The admin role / permission model is not finalized. Admin routes are gated by a configurable role flag only.