f00d311029
api_directory_admin nests permission.SUPER_ADMIN_GROUP into every new resource's _admin group. Changing it to the not-yet-existing 'god_admin' made that nesting no-op, leaving the creator as the sole member (so the access_request test's beforeAll could not remove the last member of a groupOfNames). Revert it to 'app_super_admin' and recognize 'god_admin' separately in isSuperAdmin + isAdmin. Co-Authored-By: Claude <noreply@anthropic.com>