{
  "$schemaVersion": 1,
  "_readme": [
    "The 10 active roles. Seeded by rbac-migration/seed-roles.",
    "",
    "key          matches users.role. IMMUTABLE - it is the foreign key.",
    "label        display text.",
    "description  free text shown under the role name in the listing.",
    "level        authority rank. LOWER = MORE authority; 0 is the floor, so nothing",
    "             can ever outrank the superuser and no level may be negative.",
    "             Spaced by 10 to leave room to insert. Governs who may assign or",
    "             manage whom: A can manage B when A.level < B.level.",
    "             It must NEVER gate a feature - that is what permissions are for.",
    "is_superuser bypasses BOTH the permission check and module entitlement.",
    "             Only the platform admin. Not expressible as a permission, because",
    "             a permission that overrode entitlement would break the rule that",
    "             entitlement always wins.",
    "data_scope   how much the role can see: all | agency | office | team | own.",
    "             Seeded from the tiers hard-coded in roleAccessFilter.js. Becomes a",
    "             per-resource map in phase 4.",
    "agency       CommonAgency means a system role, following the convention already",
    "             used by Languages, Areas, Provinces and DocumentsTypes. A tenant",
    "             role would carry its own agency id and shadow the system one.",
    "",
    "THERE IS DELIBERATELY NO `inherits`.",
    "The Yii hierarchy (admin -> agency_owner -> agency_admin -> agency_manager,",
    "admin -> agent) was flattened into AccessProfiles.php in phase 3, so every rule",
    "names every role that can() used to admit. auth_item needs no children.",
    "",
    "THERE IS DELIBERATELY NO `permissions`.",
    "Grants live in the rolepermissions collection, which already exists and has a",
    "different lifecycle: role metadata is ours, grants belong to the agency admin."
  ],
  "roles": [
    {
      "key": "admin",
      "label": {
        "en": "Super admin"
      },
      "level": 0,
      "is_superuser": true,
      "data_scope": {
        "default": "all"
      },
      "status": "active",
      "note": "Platform administrator. Level 0 is a floor - nothing can outrank it, and no level may be negative. The only role with is_superuser.",
      "description": "Platform administrator. Bypasses permission and entitlement checks."
    },
    {
      "key": "agency_owner",
      "label": {
        "en": "Agency owner"
      },
      "level": 10,
      "is_superuser": false,
      "data_scope": {
        "default": "all"
      },
      "status": "active",
      "description": "Tenant root. Full access across the agency."
    },
    {
      "key": "agency_admin",
      "label": {
        "en": "Agency admin"
      },
      "level": 20,
      "is_superuser": false,
      "data_scope": {
        "default": "all"
      },
      "status": "active",
      "description": "Full operational access including users, roles and settings."
    },
    {
      "key": "senior_manager",
      "label": {
        "en": "Senior manager"
      },
      "level": 30,
      "is_superuser": false,
      "data_scope": {
        "default": "team"
      },
      "status": "active",
      "description": "Manages across offices; sees their whole reporting line."
    },
    {
      "key": "agency_manager",
      "label": {
        "en": "Agency manager"
      },
      "level": 40,
      "is_superuser": false,
      "data_scope": {
        "default": "team"
      },
      "status": "active",
      "description": "Manages a team; sees their own reporting line."
    },
    {
      "key": "agent_medium",
      "label": {
        "en": "Agent medium"
      },
      "level": 50,
      "is_superuser": false,
      "data_scope": {
        "default": "own"
      },
      "status": "active",
      "description": "Front-line agent with wider account operations."
    },
    {
      "key": "agent",
      "label": {
        "en": "Agent"
      },
      "level": 60,
      "is_superuser": false,
      "data_scope": {
        "default": "own"
      },
      "status": "active",
      "description": "Front-line agent. Own records only."
    },
    {
      "key": "admin_agent_light",
      "label": {
        "en": "Agent light"
      },
      "level": 70,
      "is_superuser": false,
      "data_scope": {
        "default": "own"
      },
      "status": "active",
      "note": "Holds only edit_account today. Was commented out of the role list despite appearing in 54 access rules.",
      "description": "Narrow role: account editing only."
    },
    {
      "key": "partner_manager",
      "label": {
        "en": "Partner manager"
      },
      "level": 80,
      "is_superuser": false,
      "data_scope": {
        "default": "own"
      },
      "status": "active",
      "note": "External. Pairs with users.type = 'partner'.",
      "description": "External partner manager. Sees what their agency produced."
    },
    {
      "key": "partner_agent",
      "label": {
        "en": "Partner agent"
      },
      "level": 90,
      "is_superuser": false,
      "data_scope": {
        "default": "own"
      },
      "status": "active",
      "note": "External. Pairs with users.type = 'partner'.",
      "description": "External partner agent. Own records only."
    }
  ]
}