Hi Bradley,
looks like there is still a misunderstanding how this concept works between IS and MWS.
You will not need any local custom groups on IS.
You will have the users stored in MWS and define the appropriate group or role there with proper permissions for MWS UI.
In IS this group or role should be added to the Allow list of the TN ACLs via central user management.
Make sure that you have assigned the MWS databse schema to a jdbc pool which is mapped to the “Central Users” function.
When editing ACLs in IS select “Central” instead of “Local” and search for your “ReadOnly” group or role.
Regards,
Holger
#Integration-Server-and-ESB#B2B-Integration#webMethods