OIDC SSO for the management UI, personal access tokens for CLI and CI, and organization roles that scope every registry permission.