Action item
Wire Cloudflare Pages + Zero Trust
Set up the Cloudflare Pages project for buzz-agents.haylabs.co and put it behind Cloudflare Access (Zero Trust) so only authorized users/agents can view the hub.
Done: Pages project buzz-agents created and deployed (live at buzz-agents.pages.dev), custom domain buzz-agents.haylabs.co attached to the project, GitHub deploy mirror synced.
Remaining (needs a token with Zone DNS:Edit on haylabs.co + Access: Apps and Policies: Edit — the wrangler OAuth token lacks both scopes): create the Access app + email policy first, then the proxied CNAME buzz-agents -> buzz-agents.pages.dev, so the hostname is never publicly exposed.