Sharpens SPF.13 with what was measured on 2026-09-22 rather than surveyed. The manifest carries 55 Permission rows using exactly three values - Reader, Contributor, Owner - and those three are doing the work of TWO distinct SharePoint concepts. A RoleDefinition is a permission LEVEL and SharePoint ships Full Control, Design, Edit, Contribute, Read, Approve, Manage Hierarchy, Limited Access and Restricted Read. A SiteGroup is a set of PEOPLE and SharePoint ships Owners, Members and Visitors. A role ASSIGNMENT binds one to the other on a securable object. Ours collapses all three ideas into a single attribute, so there is nowhere to say that a group exists, nowhere to put a person in one, and no level between Read and Full Control - no Approve, which the approval module actually needs, and no Design. SEPARATELY, the platform has a SECOND role ladder in MinimumRole - Assistant, Member, Lead, Manager - which is about what an agent may invoke rather than what a principal may read. Those two ladders are not the same thing and should not be merged; the point of naming this is that today a reader cannot tell which question a Role attribute is answering. The people half of this shipped in the same cycle - ContentType.Person now carries Manager, JobTitle, Department and Responsibilities, so who reports to whom and who owns what are answerable. What is missing is who may DO what.