One authenticated administrator
The local bootstrap command creates the only administrator without placing a password in shell arguments or environment variables. Passwords use Argon2id. Sessions are stored as hashes, rotate after authentication, expire, can be revoked, and are protected by same-origin request controls.