Grant and revoke a set of a role's permissions together.
Every change is applied in one transaction: if any one is refused, none of them are made and the role keeps exactly the permissions it had. Each change is checked as a single grant or revoke would be, so granting needs admin.role.create and revoking needs admin.role.delete.
Granting a permission the role already holds, or revoking one it does not, is not an error; it is counted as unchanged. Naming the same permission in both lists is refused. Where an approval is required for these changes, the ones held for it are counted rather than applied.
Returns the role’s id and how many permissions were granted, revoked, unchanged and held for approval. The System Administrator role holds every permission and cannot be narrowed, and the Platform Support role cannot be changed at all.

