Read-only ops dashboard over /biometric/stats. Aggregate counts + recent state-change events. Auth via legal-tier token (sessionStorage; clears on tab close).
/biometric/stats