Three roles: platform admin (full SaaS), customer admin (tenant-scoped), customer operator (read-only). Email invitation flow for tenant user onboarding. 6 new requirements (RBAC-01 through RBAC-06). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>