Who can do what, in which tenant.
The platform's trust spine. An organization (tenant) is entitled to a set of modules
(via_tenant_features); roles grant
read / write / admin per module; and every grant is capped by the tenant's entitlement — a module the tenant
hasn't opted into is unreachable no matter the role. Pick a tenant and a role to see the effective permission matrix.