Privileges Required to use SubjectIsolationGroups 
SubjectIsolationGroups is a mapping that allows you to see which users are in which isolation groups.
To use SubjectIsolationGroups, you need either:
scheduler-administrator role
system goup-level permissions
You need the either of the following privilege ranks to be able to create SubjectIsolationGroups:
Create - allows you to create an SubjectIsolationGroup on the level the privilege was granted (system, partition, isolation-group), you have no further privileges through this rank, you automatically get privileges on SubjectIsolationGroups you create.
Edit - allows you to create, view, and edit all SubjectIsolationGroups on the level the privilege was granted (system, partition, isolation-group)
Delete - allows you to create, view, and delete all SubjectIsolationGroups on the level the privilege was granted (system, partition, isolation-group)
All - full control over all SubjectIsolationGroups on the level the privilege was granted (system, partition, isolation-group)
To successfully edit a SubjectIsolationGroup, you have to have either of the following privileges:
Edit - privilege rank on the SubjectIsolationGroup, or on SubjectIsolationGroups in its partition, isolation group or system-wide
Delete - privilege rank on the SubjectIsolationGroup, or on SubjectIsolationGroups in its partition, isolation group or system-wide
All - privilege rank on the SubjectIsolationGroup, or on SubjectIsolationGroups in its partition, isolation group or system-wide