The "raw_app_meta_data" stored for a user is not writeable by the user, so you can store roles and/or privileges in there.