Provision students — A-Level
Create Firebase Auth users and grant them A-Level entitlements + all boards + 12 months' access. Idempotent — existing users are updated in place.
Shared backend — the
provisionStudent callable is shared with IB. Passing board:"alevel" in the payload stamps the correct entitlements (alevel_pro, alevel) on the paid_users doc.