root_admin
The platform owner — creates tenants, assigns modules, sets pricing, and decides what a tenant's superadmin is allowed to have.
Core capability
superadmin
The owner of a tenant company — creates roles beneath them (admin, manager, employee, or anything custom) and delegates permissions.
Unlimited dynamic roles
Tenant-wise, module-wise permissions, with each employee placed on a real reporting-line tree — not a flat, fixed role list.
The delegation rule
A role can never be granted a permission its creator doesn't already hold. This is enforced in the same service every role-creation path goes through — not just hidden in a UI.