Server-enforced access control & permission-driven UIs
RBAC models for 4 roles — Super Admin, Admin, Company, Partner — enforced strictly server-side on every API endpoint and reflected in the UI: separate dashboards per role, permission-based rendering, role-scoped data visibility, and contact fields masked where a role shouldn't see them.
