We are using TAC_PLUS as our tacacs server and we have made changes to Tacacs server for better control so when user is in config mode he can run some commands while not execute some command we were able to achieve this on XE router by enabling "aaa ...