I'm having trouble with user privilege, specifically trying to restrict a user to a specific application profile. I've been using a combination of a role and a security domain, even with an RBAC role applied to the security domain, but the only progress I've seen is giving access to the entire tenant's tree instead of the one branch, a specific application profile, that I want to grant access to. Even if the user can see the others and only have access to one application profile that would be fine.