Thanks for taking a look! Yeah, not having admin access is definitely a problem. Using a PAT is an interesting idea that I'll have to think about that from a security and liability perspective.
Compliance is a PITA but it's a real thing for companies. How are you planning on clearing that hurdle? I wouldn't want to put you through the vendor survey gauntlet and SOC2 is a lot to ask of a solo dev but the aforementioned IT team could likely be persuaded if you did Type 1 at least.