- /roles — role table with create dialog and a permission-matrix sheet:
collapsible per-module sections (selected/total counts, role's own
modules start expanded) and a key/description filter that force-
expands matches; super-admin role is read-only
- /admin-users — user search (Enter to run) with role assignment
dialog; editing your own roles is blocked
Both nav items gate on auth:role:* keys, which only super-admin holds.
Co-Authored-By: Claude Fable 5 <[email protected]>