Roles
Customer access roles, derived from the system.grants access-policy table — there is no system.roles.
Roles are grants, grouped
A role exists exactly as long as some grant names it — grant a relation to a role and the role appears here; revoke the last grant naming it and the role vanishes. The role value is the auth-gate role claim, which maps an authenticated session to what it may access.
These are customer roles from the application auth gate. They are distinct from database users & roles — the operator/login identities of ADR-042, a separate governance surface that is not yet built.
Roles
…livesystem.grants · live| Role | Relations | Granted verbs | |
|---|---|---|---|