Roles permitted to START a run at the HTTP route — the coarse start-role gate
every host applies to POST /runs, before any per-workflow allowedRoles check.
A strict subset of APPROVAL_ROLES; reviewer/viewer are review-only. A
host-level concept (breakwater has no equivalent), so there is no cross-package
mirror to keep.
Roles permitted to START a run at the HTTP route — the coarse start-role gate every host applies to POST /runs, before any per-workflow allowedRoles check. A strict subset of APPROVAL_ROLES; reviewer/viewer are review-only. A host-level concept (breakwater has no equivalent), so there is no cross-package mirror to keep.