We've seen a couple of issues asking about how to validate roles on the server side. Though I don't think this add-on should be opinionated on the server-side implementation, it could be useful to suggest how to implement this on the server (can-can-can, can-can for node, home grown, etc.)