Currently the options around user permissions security are within either the Microsoft settings or within the SQL connections.
A system administrator could use active directory to control who has access to the app.
Also, if you are using Windows authentication for SQL connections you could give some Users access to certain replenishment queries and even control what is returned to the app based on the User accessing the data.