role management is very basic right now, we should add the ability to create and assign more complex roles (e.g auth by tags/metadata)