E-1 security set-up
Hypothetically, we want to allow a user into (only) 40 objects, all within a single role. But the role itself has 75 objects within it. Is the easiest way to handle this to give the user the role but then disallow the 35 unwarranted objects (or presumably, to NOT give the user the role and then set-up the 40 user/objects combinations they need)? Understanding that another option is to break-down the single role into multiple roles as well, and then follow the above logic from there, we're just looking for the most efficient way E-1 users have found to set-up