<!-- LOVABLE:BEGIN -->
> [!IMPORTANT]
> This project is connected to [Lovable](https://lovable.dev). Avoid rewriting
> published git history — force pushing, or rebasing/amending/squashing commits
> that are already pushed — as it rewrites history on Lovable's side and the
> user will likely lose their project history.
>
> Commits you push to the connected branch sync back to Lovable and show up in
> the editor, so keep the branch in a working state.
<!-- LOVABLE:END -->
- Client proposals are data-driven: one `ProposalData` record per client renders through `ProposalView` at `/propuesta/$slug`; the hand-built JERC and Urban Box pages stay untouched. Why: new clients need no code changes.
- Editor access is checked through the `has_role` admin role on every server function, not only in the UI. Why: the editor pages are UX, the server functions are the security boundary.
