Rights management via roles

tbd