The functions that a user can access are determined by the permission profile(s) assigned to the user. The ability to assign multiple permission profiles to a user reduces the administrative overhead by reducing the number of profiles required to satisfy all user access requirements.
When you create permission profiles you should consider the different user classes in your company. For example, Customer Service Representatives need to have access to customer records, but your company wants to restrict the ability to delete customer records to supervisors. To implement this you may set up a CSR profile with access to the customer records and a Supervisor profile with permission to delete a customer record. You would then assign the CSR profile to your reps and the CSR profile PLUS the Supervisor profile to supervisors.
Configuring permission profiles is a two-step process. First you create a new profile, and then you enable/disable the various permissions as needed.
Adding and Configuring a Permission Profile
To create and configure a permission profile:
Access the Permission Profiles node in the Admin Console.
(More)
To access permission profiles:
Open Admin Console and access Security > Profiles.
Double-click Permissions Profiles. This displays the Permissions Profiles window. Selecting a profile displays the corresponding permissions in the right pane.
In this case, the Admin profile is displayed.

Add a new profile.
(More)
To add a new profile:
Access Permission Profiles.
Right-click in the list of profiles list and select New. This displays the New Profile window.

Enter a profile name (required).
Enter a description (optional).
Click OK.
Configure the permissions for the new profile.
(More)
Permissions are grouped in four main categories:

Application. Everything to do with CostGuard.
Confidential Information. These options include edit and mask (hide) settings for such information as bank account numbers, social security numbers, etc.
Object. These are automated processes such as work flows and execution plans. If these are turned off, a user cannot do anything. Since the default for these is off, they should be turned on.
Reports. Access to specific reports can be limited to groups.
Each of these categories is further subdivided into more detailed categories.
For example, Applications has a sub-category named CostGuard Client, which is further subdivided into Customer Management, Accounts Receivable Management, and so on.
Note
Permissions are disabled (red) by default.
Permission Colors
Enabled permissions are green.
For a permission to be enabled, all nodes in the path must be enabled.
Disabled permissions are red.
Note
If a permission is prefaced by Deny, enabling that permission denies access to the related functionality. For example, if you enable Deny under Admin Console > Security, the Security node for users assigned to that profile is not displayed when they access Admin Console.

Configuring Profiles
To enable/disable permissions for a profile:
Access Permission Profiles.

Select the desired profile from the list.
Right-click on a permission In the permission tree and select Toggle to switch between enabling and disabling an individual permission.
Note
For a permission to be enabled, all nodes in its path must be enabled.
If a selection is the parent of other permissions, you can enable or disable the parent and all its children:
Toggle enables you to turn on, or turn off, permissions for the selected node for a permission profile.
Enable Path allows you to turn on, or enable, permissions for the selected node and its parents.
Enable Branch allows you to turn on permissions for the selected node and its children.
Disable Branch allows you to turn off permissions for the selected node and its children.