Parameterize the HCP root for seahaven-dev with schedules, PITR, alarms, and Paychex gated off so a second env does not clone production cost or side effects.
* fix(auth): accept federated portal Cognito tokens for meals admin
Google Workspace federation stores email_verified=false, which 403'd the
portal Admin probe while the public menu still loaded.
* fix(iam): grant plan role CloudFront DescribeFunction
* feat(iam): import hcptf roles into app Terraform (PLAT-146)
Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.
* fix(iam): add apply-role IAM list permissions (PLAT-146)
IamReadOnly omitted ListRoleTags and ListInstanceProfilesForRole needed after detaching the substrate guardrail.