SAM provides role-based security privileges on design objects and columns defined in an ORS.
An IDD application uses this security configuration so that the data that is shown, and the operations that are available to an individual user, depend on the role(s) assigned to that user account. IDD application users see only the data and functionality to which they have been granted access. For example, if a user does not have READ access to the HISTORY table for a base object, in the IDD application, the History command for that subject area is not available to the user.
A Hub user with Administrator access (configured in the Users tool in the Hub Console) is a super-user for IDD and has full privileges on all objects.