A role-by-role audit of who can do what across the backend API, the
admin frontend, Better Auth, the photo API and the deployment config.
It records the effective permission matrix for admin, organizer, staff
and marketing, where the frontend drifts from what the API actually
allows, and a prioritised remediation plan.
Committed as a reference for that remediation work; the findings in
section 11 describe the current state, not fixes.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>