If you are using the Profile Generator, you can automatically generate authorization profiles based on selectable R/3 transactions. You can also generate these type of profiles for administrators using templates.
For reasons of system security, you should divide up system administration tasks between different administrators as described below.

The superuser sets up user master records, profiles and authorizations for administrators in one or more areas.
An area may be a department, a cost center or any other organizational unit.
Within an area, administration tasks are divided among the following three administrators:
User administrators have authorizations to do the following:

They are not authorized to:
Authorization data administrators have authorizations to do the following:

They are not authorized to:
Authorization profile administrators have authorizations to do the following:

They are not authorized to:
For information about assigning administration tasks to the various users see
Setting Up Administrators.You can use authorization objects S_USER_AGR and S_USER_TCD to further differentiate the roles of the administrators.