i.e. keep an audit log of changes, associated with the signed in user. perhaps verify they are in `traffic-staff`, `librarian`, `sudoer`, etc. see: * https://github.com/erlef/oidcc * https://hexdocs.pm/openid_connect/readme.html