AFTER INSERT ON permission: grant the code to S roles for that app and to global S roles (app_code NULL), then materialise affected user grants.