"*" admin group has access to everything. The permissions create, read, update, and delete are the full set that is available, and "all" is a shortcut to include all permissions. "admin" ["all"] "ALL" everybody group has basic access to the system. "everybody" ["all"] "BASIC" everybody group can read all process groups and process models. "everybody" ["read"] "PG:example" everybody can start all models "everybody" ["start"] "PG:example"