Application management : Accounts : Authorization settings : Separating data access and functional access (splitting role and data)
Separating data access and functional access (splitting role and data)
Procedure
1. Go to Accounts > Authorization settings.
2. Assuming Authorization is already set to Yes, set Split role and data to Yes also.
3. Create data user groups and functional user groups.
4. Link users to functional user groups and data user groups.

The result of the Split role and data setting is that in Authorization > User groups, the Function profile field is no longer a mandatory field. Consequently, it is possible to have user groups without linked function profiles.
By linking an authorization filter to a user group without a function profile, you can grant data access to a specific data set (data access).
Applying authorization in this manner has functional implications, as is explained in Authorization methodology differences.
* 
After setting Split role and data to Yes, it will be difficult / near to impossible to revert this change.