It would be a good practice to check if ROLE_SYSTEM gives at least one effective business-oriented role. Where? `BasicApplicationCoreSecurityConfig`? When? Server start?