e2ae791fa2
Previously only provincial_admin could edit roles/permissions in the UI. Now admin (city-level admin) role can also edit. The backend already enforces fine-grained permission checks, so the UI gate just needs to match can_manage semantics.