Allow SecurityIdentity to carry an immutable map of names to role mappers.
Allow SecurityIdentity to be queried for category roles (defaulting to the empty role set).
Allow a new SecurityIdentity to be created from an original SecurityIdentity, with a new role mapper for a given category name, if the calling class has adequate permissions.
Allow SecurityDomain to specify an initial default set of names to role mappers.