Note: Permissions are registered from application routes on deploy (
system:deployed).
Role grants are managed in Admin → Roles. UMS is the sole access source — there is no local permission fallback.