- Introduce organization-scoped roles that can be created, updated, and deleted per organization via the Management API or Dashboard.
- Enable assigning these org-scoped roles to users, enterprise groups, and pre‑assigning them during user invitations.
- Tenant‑wide RBAC remains unchanged for tenants not using the new org‑scoped roles.