By assigning a user to a group, a contract owner or administrator not only defines which actions a user is authorized to perform in the DCD, but also which resources (virtual data centers, images, snapshots, IP blocks) members of this group can access.