V190: the active role lives on the session, and roles have an order.
Two additive columns for PhoenixKit.Users.ActiveRole
(dev_docs/guides/2026-09-13-active-role.md):
phoenix_kit_users_tokens.active_role_uuid uuid NULL— the role a session acts as. Per token, so a user can be Admin on one machine and Seller on another, an impersonation session has a role of its own, and a second multi-session account starts fresh.NULLmeans "the default": the first switchable role the user holds, in role order. Nothing is written until the user actually switches. No foreign key: the value is validated on every read (ActiveRole.resolve/3only ever returns a role the user still holds), a role cannot be deleted while assigned, and removing a role from a user revokes the sessions acting as it (Roles.remove_role/3) — so a dangling uuid cannot outlive the assignment that made it meaningful.phoenix_kit_user_roles.position integer NOT NULL DEFAULT 0— the operator-defined role order. Seeded Owner = 0, Admin = 1, User = 2, custom roles after them in creation order. It decides the default role of a new session and the order the role switcher lists roles in; the Roles admin page reorders it.
Additive only: no drops, no reshapes of anything the ExpectedSchema
manifest already declares.