Data-driven architectures are very relevant, in particular in a corporate / business environment.
I found all the answers in the docs.
A SQL Schema can carry a custom query, it's called a view.
A SQL Schema can carry a custom algorithm, it's called a function or a generated column.
You can always deactivate permissions on a table to not expose it, my bet is that your backoffice will need to though.
On top of that, Hasura supports custom resolvers (code driven endpoints).
Finally you can stitch 2 GraphQL schemas together. It doesn't have to be one size fits all. So even if only 50% of your app can fit in the model of Hasura, you can always mix and match. It's still 50% that will be up and running in minutes.