Drafts a comprehensive task specification for implementing zero-trust scope guards on internal API routes and SSR UI pages, as requested. The file adheres strictly to the repository's Kanban and Markdown metadata guidelines. Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>