Sign-in needs a session secret and at least one provider. Email sends a link through Resend. The link expires in one hour and works once. The same address can request a new link once a minute.
Google sign-in uses an OAuth client. A verified Google address is linked to an existing account with the same email, so one person can use either method when both are configured.
After the first sign-in
The address in ADMIN_EMAIL becomes the admin when that person signs up. Later signups email that address when Resend is configured. Everyone else is a member.