Signed-in members land in their project role. If the token role shows authenticated, the email is not in sandbox.members yet.
No checks run yet.
Use the Supabase JS client with the URL and publishable key above, call signInWithOAuth({ provider: 'azure' }), then query with .schema('wh') or .schema('<your schema>'). Wage and pay data never exist in the sandbox; use wh.synthetic_rates for labor-cost prototypes.