The backoffice that owns every word on the public site, including the ones in this paragraph.
A separate Next.js application, authenticated and never prerendered, that administers all the content of the public site: posts and their translations, series, projects, the profile, the technology and contact catalogs, comments, contact requests, visitors, the agent configuration and its budget, users, roles and permissions. Access is gated per module by a permission map shared between the navigation and the route guard, and the same permission codes are enforced again on the API side.
Editing content by hand in the database is fine exactly once. After that you need a person who is not a DBA to be able to publish a post on a Tuesday without opening a SQL client.
A single backoffice where every list is the same generic table component with server-side paging, sorting and search, every destructive action goes through the same confirmation dialog, and every screen is behind a module permission. The interface is deliberately in English, because it has one user and that user reads English.
A shared table component pays for itself at the third screen, not the first, which is why three modules still carry their own inline table and are waiting to be migrated. Writing the divergence down in the project rules, instead of fixing it quietly during an unrelated task, is what keeps it from being rediscovered every few weeks.