UpdateUserAction and CreateUserAction were calling syncPermissions() which wrote to model_has_permissions table directly. This meant permissions persisted even after being removed from the role. Now users only get permissions through their roles.