Bekaert uses AzureAD for authorizing their users to access Cumulocity.
Based on attributes in the directory it is possible to assign users a Global Role.
End users however only are allowed to see their own "business unit" / production line. We have setup device groups according to their plants and production lines.
We would like to be able to assign inventory roles to global roles in order to give the users only access to the dashboards for their own plant or production line.