Access
Access has two layers. Platform roles and users administer the website in the admin panel, API, and MCP. Website roles and users are signed-in visitors on the public site, backed by a user-kind object type. Object-entry grants stay role checkboxes (own vs others). Optional structured conditions on a grant further restrict which entries match — for example the same department as the viewer, or mutate only within 30 minutes of creation. Empty conditions keep today's RBAC behavior. Super-admin, site-wide platform flags, and HOC operator roles stay boolean.
Reads need website access. Creating platform roles, changing platform user roles, and managing website roles generally require website superadmin.