Start with a simple front door: sign in, land on your internal workspace, and launch the apps that run the firm.
The portal is still using the default local credentials from .env.example. Before this goes anywhere public, set a real username, password, and session secret.