The /admin group rode on webAuthMW + audit only; just the securitySettings sibling checked the role. Inert today (login mints role=admin), live the day RBAC lands — one group-level gate beats per-route annotations to forget.