I see in a couple of spots where you call out "Admin" for purposes of Role-based Authorization. But I do not see where you incorporate Group in any authorization handshakes. Have I missed something, or is that handshake TBD? Via the AuthorizeAttribute mechanism? Or other Startup request pipeline?