Access
Access has two layers. Platform roles and users administer the website in the admin panel, API, and MCP. Website roles and users are signed-in visitors on the public site, backed by a user-kind object type.
Reads need website access. Creating platform roles, changing platform user roles, and managing website roles generally require website superadmin.