Setup needed

Connect the candidate workspace.

Set JOB_FINDER_CANDIDATE_ID to the Candidate ID used by the matching runtime. Production authentication belongs at the API boundary rather than trusting a Candidate ID from browser state.