Hi Hannu,
There are a couple of ways to achieve this:
- Create site-based security groups and assign users to the appropriate groups based on the sites they should have access to.
Or
- Use Object Restrictions in the Security Groups application to restrict user's access to a specific subset of data based on your requirements.
The best approach depends on whether your access requirements are primarily site-based or data-based.