Introduce a central access policy that lets authenticated non-staff users view
backup status pages while keeping credentials, logs, configs, and mutating
actions staff-only.
Hide sensitive navigation and host controls for read-only users, expose only
the status API to authenticated viewers, and document the two access levels.