QA engine

Credentials

Logins the agent uses, stored encrypted and referenced from scenarios by role name — never written into scenario files. Passwords are write-only: once saved, they can be replaced but not read back.

Stored roles

Add a role not yet configured: subsidiary_contract_manager, subsidiary_approver, head_office_admin, head_office_viewer, supplier_member