Separation of duties
Is it possible to use some combination of user privileges and administration groups so that one group of users can only manage targets in their own group? For example, database administrators could manage only databases and underlying host targets, and middleware administrators would manage only targets relevant to their duties. Viewing targets outside their own domains would also be allowed.