You're on the right track, you need to create specific roles and then add them to user groups. Then start adding users.
If you add some of the ones predefined you'll get a lot of other permissions so you can create your own from scratch
HTH
java
if this helps, please rate
www.cisco.com/go/pdihelpdesk
HTH
java
if this helps, please rate