FLS8 — the system user is NOT exempt; its access is DATA (4.5). The aggregation has no
identity branch: the account reads every column of the restricted entity because snapshot
initialization wrote Allow rows for the standard roles it holds — so with the bundle's
tightenings in place (which never touch system-user roles) its denied set must be empty.
FLS8 — the system user is NOT exempt; its access is DATA (4.5). The aggregation has no identity branch: the account reads every column of the restricted entity because snapshot initialization wrote Allow rows for the standard roles it holds — so with the bundle's tightenings in place (which never touch system-user roles) its denied set must be empty.