A locked product is served white-label on its own domain (and shipped as its own
native app) with no indication FuzeFront is underneath — while still consuming the
platform's authN, authZ, billing, payments, notifications, and sockets. Approving these frames
approves the mode: locked + branding + native manifest
model before any UI is implemented. Built in the fuse-seam design-system tokens.
Locked-domain sign-in — product brand only, FuzeFront hidden; auth served same-origin.
Product runs full-screen with its own chrome — no launcher, org-switcher, or return-to-portal.
375px white-label surface with touch nav + safe-area — the TWA viewport.
Each product is its own installed app (own package id) — the Google/Zoho/Atlassian model.