admin user list [--state active|pending|disabled|admin] [--limit] [--cursor] and admin user show <name>, SSH-only, refused to non-admins.
Show carries keys with last use, emails with how each was verified, PGP keys, org roles, owned repo count, API token names, and live web session count. last_seen on both is the newest last_used_at across the account's SSH keys and API tokens.
Wiki: Admin page documents both under "Audit and account control"; pushed with the merge.
Closes #69