The user has a way to identify himself to the application. All authenticated users can make full use of the application (there is no authorization for different actions on the application, at least in this versio).
Only users belonging to the group opsmanagement (it has to be created) are authenticated in the application.
Result: The user can use the application