server: replace global CSRF allowlist with per-route posture helpers
Add sandbox mode: ephemeral creator accounts for dashboard exploration
Restructure into monorepo