Go to Administration
Go to Rolls

Within the roll, you have different permissions

Within every Menu, you have to define what a user might see or do
In above example for File Management, user is not allowed to
- Run a process from Credit notes
- Load dossier JSON data
- Edit commission of a file.
You need to validate for each module, that user group has the right (and restricted) access to all items