Adds the seahaven-lambda-execution-boundary policy as a
PermissionsBoundary on all auto-generated Lambda execution
roles via Globals.Function, enabling the cfn-execution-role
scope-down from INFRA-97 to safely allow iam:CreateRole.
No explicit AWS::IAM::Role resources exist in this stack;
the Globals entry covers both SlaMonitorFunction and
UserSyncFunction.
Refs: INFRA-103
Consolidates front-sla-monitor (Python SAM) and google-user-sync
(JavaScript CDK) into a single Python SAM repo with two Lambdas:
front-sla-monitor and front-user-sync.