Audit the admin plane itself
Access is via either a static admin API token or an admin-specific JWT issued at login
There are two supported ways for an admin to prove who they are: a fixed API token for automated tools, or a signed session token issued after logging in.
Both are checked the same way once a request reaches the admin routes.

