Permissions
The permission catalog, and a bulk capability check for the calling user.
Get permission catalog
Returns permissions grouped by role, filtered by the given roles: only the requested role groups appear. Without a roles parameter returns the full catalog.
Bulk capability check
Reports, for each user code, whether they currently hold the given permission. Read-only; never grants. Used by setup UIs to warn when a selected approver lacks a capability.