RBAC permissions for SPA app and API

This question seems to be related to this one, therefore linking: