Add Windows install + API-key permission operator docs
Summary
Two operator-facing reference docs covering the 1.7.0 install-resilience + permission-hint surface (PR #329 + #330):
- `docs/windows-tentacle-install.md` — quick-start, UAC + elevation behaviour, custom install paths, 5 common failures + remediation, air-gapped install, reinstall / upgrade flow, full uninstall sequence, reference table.
- `docs/api-key-permissions.md` — core model (API key binds to user, not permission), 10-row operation→permission matrix, built-in role table (System Administrator deliberately lacks MachineCreate, documented inline), three remediation paths for 403, structured 403 response shape, audit + revocation, best practices.
Both docs cross-link each other and cite source-of-truth files (`BuiltInRoleSeeder.cs`, `PermissionRoleResolver.cs`, `WindowsPowerShellScriptBuilder.cs`).
Test plan
-
Doc-only PR — no code changes -
Operator review — confirm troubleshooting scenarios match real-world flows
Depends on PR #329 (install-info.json + UAC auto-elevation) + PR #330 (structured 403 response) for the behaviour the docs describe.