1- Data protection api keys must be stored in shared storage like database so scaled out apps would be able to issue/validate jwt tokens of different instances of the same app
2- Prevent built-in roles from modification/deletion
3- Role's page needs minor localized strings improvements