User should be able to confirm email before anything else. Should only get a `user` role if confirmed.