Design exactly what each role can see, do, and approve — one clear control, repeated across every app.
Every role, side by side. The column for the role you're editing is highlighted. Read across a row to see how a single permission widens with seniority.
Two kinds of rule layer on top of roles. Grants add access; Restrictions remove it. When they conflict, restrictions win — and only Owners can create one.