Ааа, я кажется понял. OU я имел ввиду в write scope для ограничения.
Не, так то да, создана группа, туда добавлен пользователь. Группа как член кастомной role group.
In addition to linking role assignees to roles, role assignments can also apply custom or built-in management scopes. Management scopes control which recipient, server and database objects can be modified by role assignees. If this role is assigned to a role assignee, but a management scope allows the role assignee only to manage certain objects based on a defined scope, the role assignee can only use the permissions granted by this role on those specific objects.