Surface logic, that's the hierarchical access on the forum app.
For instance, the highest level of access belongs to the moderators of each forum.
They can set rules, mute users, delete posts, and establish sub-moderators for topic subsections, but they can't change the overall operation of the forum app. They can only act according to the app's operational rules, possessing only the rights to use, not to modify the app, nor to view the content of other forums.
The second-highest level of access goes to the sub-moderators of the various topic subsections beneath the moderators.
This is akin to a department manager.
They can only manage their own department.
Staff permissions belong to registered members.
They can speak freely on the forum, but can't manage anything. They are merely users.
Temporary permissions belong to visitors.
That doesn't need explaining.