These privileges are set up in the role's login shell by default. They are inherited from parent processes of this role's processes. The privileges are applied to every program that the role runs, except for programs that have been given specific privileges in the Set Securities Attributes dialog box.
Note: Do not change these privileges for most administrative roles. Make changes only for special roles that are not general purpose accounts.