Roles are used to make security profiles management even more effective and rapid! The roles make it possible to group together users that perform similar tasks and therefore to manage the security profiles by Role rather than by user. Less “entity” to profile means more simplicity in implementing security regulations and simplicity of future maintenance.
For example, in defining a “Bookkeeper” role and thereby managing the security profiles on the actual role, the users just need to be associated to the role and they inherit the security policy defined for the “Bookkeeper”.
It is still possible to manage exceptions to the original role/s: the different “treatment” reserved for the user can be indicated and the Security module will apply this variation to the user desired only.