Builds on the org-wide policy model (#6625): reads/runs are open to all; create/edit/delete is gated by PolicyController.requirePolicyEditingAllowed, which was admin-only. On SaaS that's the wrong role — there is a single global admin for the whole deployment, never one per org — so org users couldn't edit policies at all. Introduce a PolicyManagementAuthority strategy: self-hosted keeps the global-admin check (AdminPolicyManagementAuthority); SaaS uses the leader of the user's team (TeamLeaderPolicyManagementAuthority -> TeamSecurityExpressions.isCurrentUserTeamLeader). The proprietary policy layer stays decoupled from the team model via the interface + profile-scoped beans.
Tests: TeamSecurityExpressionsTest (leader/member/no-membership/no-team/unauthenticated), plus delegation tests for both authority beans.