Team
Roles first. Named sets of capabilities from a curated catalog (restart/reload/start/stop a service, service status and the journal, read the logs, update packages, docker, read the firewall and sockets, reboot…), shown as the exact sudoers policy they write — allowlist-first, /etc/sudoers.d/lens-<user>, "only these" units named on the card.
Members last. A person minted the way Add a user does it (identity, key-only login, NOPASSWD sudo scoped by the role), then her servers as board cards — pick one and a role dropdown appears on the card; the card with its dropdown IS the grant. Saving stores the desired state and each assignment carries where it stands; the writer that makes the servers match it (create, key, sudoers; remove what was taken away) is the next piece. Everything key-scoped like the map; there is no "My Account" because the operator's account is the biometric and the pen drive.