- Roles: reader, mod-l2, mod-l1, admin. Grants: scope (all, poet, book/section with everything in
it, one work) x content (poets, books, works, dictionary) x actions (create, edit, delete,
arrange); dictionary grants are site-wide. can() in api/src/permissions.ts is the one check.
- Admin API and pages: role dropdown on /admin; /admin/user/:id lists a moderator's grants, adds
them (target by poet id or page link) and revokes them; demoting a moderator clears their grants;
grant and revoke go to the audit log.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>