It is useful to think of IDD security in two broad categories:
Object security: Access to subject area data, and the ability to perform operations on that data (such as view, create, update, and merge) in IDD.
Task security (workflow). Access to tasks and actions based on roles that are defined in the workflow.
Although this example scenario focuses on object security only, many of the ideas are also applicable to task security in IDD, as task security depends on SAM as well.