Protected workspace

Authorized project and equipment work requires Keyra identity and Core context. This shell does not invent a login success or a Subscription picker grant.

KEYRA_UNBOUND

Keyra identity is not connected

Keyra issuer, audience, session validation and Core user mapping.

Bind the existing Keyra sign-in contract. A token is not a Subscription grant.

This is not a simulated connection or a successful write. Protected project data is not present in this build.

Proposed tabs

Labels only. Each must bind to a registered Tab ID before it can authorize an action. Registered Tab IDs and independent View/Add/Edit/Delete/Export/Share/Approve actions.