Z/OS Connect defines an mpOpenAPI extension for an attribute x-ibm-zcon-roles-allowed here
Under this schema it is legal to define it at the top level.
If two applications have a different value at the top level, an OpenAPI merge conflict ensews. We must fix this.
This issue was raised via a PMR