Extend the permission system beyond workspace-level roles to support per-project access control and more refined scoping for External Viewer accounts. An Editor could be limited to specific projects; a Viewer could be scoped to data for a specific client.
The current four-role system (platform_superadmin, superadmin, editor, viewer) is coarse. In practice, workspaces often include contractors or part-time collaborators who should only see or edit a subset of projects. Without granular controls, the only options are full editor access or read-only access to everything — neither of which fits.