- Add dynamic authentication and subuser permission handling using `subusers_permission_node_key`. - Refactor route-level permission logic for creating, viewing, editing, and deleting bookings to respect subuser context. - Ensure proper error handling for unauthorized access and enforce departmental scope for admin-level actions.