Use this page to manage explicit app access, supported roles, and feature flags without writing SQL.
Authenticated employees remain default `viewer` users unless you create elevated access rows.
This page is restricted to `admin` and `platform_admin` users. If you believe you should have access,
confirm your `project-management` or global admin role is seeded in `app_user_profiles` / `app_user_app_access`.