In some cases you would want to restrict administrators from assign authorization to certain GL accounts to users. If these accounts are maintained with an authorization group you can restrict the admins from assigning these groups of accounts in end user roles using the authorization object: